Show filters
639 Total Results
Displaying 1-10 of 639
Sort by:
Attacker Value
Moderate

OpenSSL TLS Server Crash (NULL pointer dereference) — CVE-2021-3449

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Attacker Value
Unknown

CVE-2021-36260

Disclosure Date: September 22, 2021 (last updated November 28, 2024)
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
Attacker Value
Unknown

CVE-2023-7266

Disclosure Date: December 28, 2024 (last updated January 14, 2025)
Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE-2023-7266
Attacker Value
Unknown

CVE-2024-43052

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while processing API calls to NPU with invalid input.
Attacker Value
Unknown

CVE-2018-11922

Disclosure Date: November 26, 2024 (last updated January 13, 2025)
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
Attacker Value
Unknown

CVE-2024-38423

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while processing GPU page table switch.
Attacker Value
Unknown

CVE-2024-38422

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Attacker Value
Unknown

CVE-2024-38415

Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Memory corruption while handling session errors from firmware.
Attacker Value
Unknown

CVE-2024-33060

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when two threads try to map and unmap a single node simultaneously.
Attacker Value
Unknown

CVE-2024-33052

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when user provides data for FM HCI command control operations.