Show filters
1,551 Total Results
Displaying 291-300 of 1,551
Sort by:
Attacker Value
Unknown

CVE-2023-35956

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `fastlz_decompress`.
Attacker Value
Unknown

CVE-2023-35955

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `LZ4_decompress_safe_partial`.
Attacker Value
Unknown

CVE-2023-34436

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-34087

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-46837

Disclosure Date: January 05, 2024 (last updated February 25, 2025)
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all the writes will reach the memory. This undefined behavior was meant to be addressed by XSA-437, but the approach was not sufficient.
Attacker Value
Unknown

CVE-2023-34321

Disclosure Date: January 05, 2024 (last updated February 25, 2025)
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all the writes will reach the memory.
Attacker Value
Unknown

CVE-2023-41779

Disclosure Date: January 03, 2024 (last updated February 25, 2025)
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.
Attacker Value
Unknown

CVE-2023-32887

Disclosure Date: January 02, 2024 (last updated February 25, 2025)
In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161837; Issue ID: MOLY01161837 (MSV-892).
Attacker Value
Unknown

CVE-2023-32885

Disclosure Date: January 02, 2024 (last updated February 25, 2025)
In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issue ID: ALPS07780685.
Attacker Value
Unknown

CVE-2023-32884

Disclosure Date: January 02, 2024 (last updated February 25, 2025)
In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011; Issue ID: ALPS07944011.