Search Results (42434 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-33026 1 Qualcomm 164 Ar8035 Firmware, Csr8811 Firmware, Fastconnect 6700 Firmware and 161 more 2024-08-06 7.5 High
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-7055 2024-08-06 6.3 Medium
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.
CVE-2024-21481 1 Qualcomm 144 Aqt1000 Firmware, Ar8035 Firmware, Fastconnect 6200 Firmware and 141 more 2024-08-06 8.4 High
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
CVE-2024-21980 1 Amd 64 Epyc 7003 Firmware, Epyc 7203 Firmware, Epyc 7203p Firmware and 61 more 2024-08-06 7.9 High
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
CVE-2024-23355 1 Qualcomm 131 Ar8035 Firmware, Fastconnect 6200 Firmware, Fastconnect 6700 Firmware and 128 more 2024-08-06 7.8 High
Memory corruption when keymaster operation imports a shared key.
CVE-2024-23353 1 Qualcomm 212 315 5g Iot Modem Firmware, 9205 Lte Modem Firmware, 9206 Lte Modem Firmware and 209 more 2024-08-06 7.5 High
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-23356 1 Qualcomm 188 Aqt1000 Firmware, Ar8031 Firmware, Ar8035 Firmware and 185 more 2024-08-06 7.8 High
Memory corruption during session sign renewal request calls in HLOS.
CVE-2024-33014 1 Qualcomm 304 315 5g Iot Modem Firmware, Apq8064au Firmware, Aqt1000 Firmware and 301 more 2024-08-06 7.5 High
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33012 1 Qualcomm 240 Ar8035 Firmware, Ar9380 Firmware, Csr8811 Firmware and 237 more 2024-08-06 7.5 High
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
CVE-2023-42011 1 Ibm 1 Sterling B2b Integrator 2024-08-06 4.3 Medium
IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. IBM X-Force ID: 265508.
CVE-2022-48844 1 Linux 1 Linux Kernel 2024-08-03 5.5 Medium
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix leaking sent_cmd skb sent_cmd memory is not freed before freeing hci_dev causing it to leak it contents.
CVE-2024-38481 1 Dell 1 Emc Idrac Service Module 2024-08-02 4.8 Medium
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
CVE-2024-7331 1 Totolink 2 A3300r, A3300r Firmware 2024-08-01 8.8 High
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-41660 1 Openbmc-project 1 Slpd-lite 2024-08-01 9.8 Critical
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the slpd-lite daemon on the BMC. Patches will be available in the latest openbmc/slpd-lite repository.
CVE-2024-41950 1 Deepset 1 Haystack 2024-08-01 7.5 High
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone can create and render that template on the client machine they run any code. The vulnerability has been fixed with Haystack `2.3.1`.
CVE-2024-40946 2024-07-15 4.7 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-48737 2024-07-05 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-48736 2024-07-05 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-47581 2024-06-20 3.3 Low
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-36699 2024-06-14 0.0 Low
DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.