Show filters
1,625 Total Results
Displaying 441-450 of 1,625
Sort by:
Attacker Value
Unknown

CVE-2022-38699

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.
Attacker Value
Unknown

CVE-2022-36876

Disclosure Date: September 09, 2022 (last updated October 08, 2023)
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
Attacker Value
Unknown

CVE-2022-36857

Disclosure Date: September 09, 2022 (last updated October 08, 2023)
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
Attacker Value
Unknown

CVE-2022-36851

Disclosure Date: September 09, 2022 (last updated October 08, 2023)
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
Attacker Value
Unknown

CVE-2022-26390

Disclosure Date: September 08, 2022 (last updated October 08, 2023)
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
Attacker Value
Unknown

CVE-2022-38399

Disclosure Date: September 08, 2022 (last updated October 08, 2023)
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
Attacker Value
Unknown

CVE-2022-26468

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07168125; Issue ID: ALPS07168125.
Attacker Value
Unknown

CVE-2022-23691

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
A vulnerability exists in certain AOS-CX switch models which could allow an attacker with access to the recovery console to bypass normal authentication. A successful exploit allows an attacker to bypass system authentication and achieve total switch compromise in ArubaOS-CX Switches version(s): AOS-CX 10.10.xxxx: 10.10.0002 and below, AOS-CX 10.09.xxxx: 10.09.1030 and below, AOS-CX 10.08.xxxx: 10.08.1070 and below, AOS-CX 10.06.xxxx: 10.06.0210 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address this security vulnerability.
Attacker Value
Unknown

CVE-2021-35113

Disclosure Date: September 02, 2022 (last updated October 08, 2023)
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Attacker Value
Unknown

CVE-2021-35109

Disclosure Date: September 02, 2022 (last updated October 08, 2023)
Possible address manipulation from APP-NS while APP-S is configuring an RG where it tries to merge the address ranges in Snapdragon Connectivity, Snapdragon Mobile