Show filters
84 Total Results
Displaying 1-10 of 84
Sort by:
Attacker Value
Unknown

CVE-2021-23841

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1…
Attacker Value
Unknown

CVE-2016-0802

Disclosure Date: February 07, 2016 (last updated November 25, 2024)
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
0
Attacker Value
Unknown

CVE-2016-0801

Disclosure Date: February 07, 2016 (last updated November 25, 2024)
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
0
Attacker Value
Unknown

CVE-2013-5145

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.
0
Attacker Value
Unknown

CVE-2013-5152

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
0
Attacker Value
Unknown

CVE-2013-5151

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.
0
Attacker Value
Unknown

CVE-2013-5139

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.
0
Attacker Value
Unknown

CVE-2013-5157

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.
0
Attacker Value
Unknown

CVE-2013-5141

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to cause a denial of service (infinite loop and device hang) via a crafted application, related to an "integer truncation vulnerability."
0
Attacker Value
Unknown

CVE-2013-5147

Disclosure Date: September 19, 2013 (last updated October 05, 2023)
Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card.
0