Show filters
650 Total Results
Displaying 81-90 of 650
Sort by:
Attacker Value
Unknown
CVE-2022-27114
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.
0
Attacker Value
Unknown
CVE-2022-28471
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38
0
Attacker Value
Unknown
CVE-2022-26073
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-28705
Disclosure Date: May 04, 2022 (last updated February 23, 2025)
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a FastL4 profile that has ePVA acceleration enabled can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
0
Attacker Value
Unknown
CVE-2022-21743
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: ALPS06371108.
0
Attacker Value
Unknown
CVE-2022-20107
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID: DTV03330673.
0
Attacker Value
Unknown
CVE-2021-27439
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0
Attacker Value
Unknown
CVE-2021-27435
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0
Attacker Value
Unknown
CVE-2021-27433
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0
Attacker Value
Unknown
CVE-2021-27431
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.
0