Vulnerabilities (CVE)

Filtered by CWE-126
Total 267 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-7347 1 F5 2 Nginx Open Source, Nginx Plus 2025-01-22 N/A 4.7 MEDIUM
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2024-9843 2 Apple, Ivanti 2 Macos, Secure Access Client 2025-01-17 N/A 5.0 MEDIUM
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
CVE-2024-21477 1 Qualcomm 368 Aqt1000, Aqt1000 Firmware, Ar8035 and 365 more 2025-01-15 N/A 7.5 HIGH
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
CVE-2023-43528 1 Qualcomm 182 Ar8035, Ar8035 Firmware, C-v2x 9150 and 179 more 2025-01-15 N/A 6.1 MEDIUM
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
CVE-2023-43527 1 Qualcomm 108 Fastconnect 6800, Fastconnect 6800 Firmware, Fastconnect 6900 and 105 more 2025-01-15 N/A 6.8 MEDIUM
Information disclosure while parsing dts header atom in Video.
CVE-2023-33115 1 Qualcomm 336 Aqt1000, Aqt1000 Firmware, Ar8035 and 333 more 2025-01-13 N/A 7.8 HIGH
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
CVE-2024-45548 1 Qualcomm 20 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 17 more 2025-01-13 N/A 7.8 HIGH
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
CVE-2024-45546 1 Qualcomm 20 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 17 more 2025-01-13 N/A 7.8 HIGH
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
CVE-2024-45559 1 Qualcomm 46 Qam8255p, Qam8255p Firmware, Qam8295p and 43 more 2025-01-13 N/A 5.5 MEDIUM
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.
CVE-2024-45558 1 Qualcomm 366 Ar8035, Ar8035 Firmware, Csr8811 and 363 more 2025-01-13 N/A 7.5 HIGH
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
CVE-2023-43539 1 Qualcomm 274 Ar8035, Ar8035 Firmware, Csr8811 and 271 more 2025-01-10 N/A 7.5 HIGH
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
CVE-2023-33090 1 Qualcomm 104 Ar8035, Ar8035 Firmware, Fastconnect 6800 and 101 more 2025-01-10 N/A 5.5 MEDIUM
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
CVE-2023-33078 1 Qualcomm 26 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 23 more 2025-01-10 N/A 5.1 MEDIUM
Information Disclosure while processing IOCTL request in FastRPC.
CVE-2024-23366 1 Qualcomm 34 Qam8255p, Qam8255p Firmware, Qam8295p and 31 more 2025-01-10 N/A 6.6 MEDIUM
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
CVE-2024-33061 1 Qualcomm 18 Qcs8550, Qcs8550 Firmware, Sw5100 and 15 more 2025-01-10 N/A 6.8 MEDIUM
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
CVE-2024-33067 1 Qualcomm 154 Ar8035, Ar8035 Firmware, C-v2x 9150 and 151 more 2025-01-10 N/A 6.1 MEDIUM
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
CVE-2024-43063 1 Qualcomm 34 Qam8255p, Qam8255p Firmware, Qam8295p and 31 more 2025-01-10 N/A 6.1 MEDIUM
information disclosure while invoking the mailbox read API.
CVE-2024-23363 1 Qualcomm 250 Ar8035, Ar8035 Firmware, Csr8811 and 247 more 2025-01-09 N/A 7.5 HIGH
Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.
CVE-2017-17772 1 Qualcomm 14 Sd 450, Sd 450 Firmware, Sd 625 and 11 more 2025-01-09 N/A 9.8 CRITICAL
In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
CVE-2018-5852 1 Qualcomm 46 Mdm9206, Mdm9206 Firmware, Mdm9607 and 43 more 2025-01-09 N/A 8.4 HIGH
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'