Show filters
526 Total Results
Displaying 11-20 of 526
Sort by:
Attacker Value
Unknown

CVE-2024-33067

Disclosure Date: January 06, 2025 (last updated February 27, 2025)
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
Attacker Value
Unknown

CVE-2024-56033

Disclosure Date: January 02, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs allows Reflected XSS.This issue affects FAQs: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2024-54246

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs allows Stored XSS.This issue affects FAQs: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2024-50404

Disclosure Date: December 06, 2024 (last updated February 27, 2025)
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later
0
Attacker Value
Unknown

CVE-2024-54137

Disclosure Date: December 06, 2024 (last updated February 27, 2025)
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data. This results in an incorrect shared secret value being returned when the decapsulation function is called with a malformed ciphertext. This vulnerability is fixed in 0.12.0.
0
Attacker Value
Unknown

CVE-2024-52455

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoQSystem Inc. GoQSmile allows Reflected XSS.This issue affects GoQSmile: from n/a through 1.0.1.
0
Attacker Value
Unknown

CVE-2024-43052

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption while processing API calls to NPU with invalid input.
Attacker Value
Unknown

CVE-2024-33056

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Attacker Value
Unknown

CVE-2024-33053

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption when multiple threads try to unregister the CVP buffer at the same time.
Attacker Value
Unknown

CVE-2024-33044

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.