Show filters
666 Total Results
Displaying 111-120 of 666
Sort by:
Attacker Value
Unknown

CVE-2022-34326

Disclosure Date: September 27, 2022 (last updated October 08, 2023)
In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer task and RX task would be locked when there are frequent and continuous Wi-Fi connection (with four-way handshake) failures in Soft AP mode.
Attacker Value
Unknown

CVE-2022-26529

Disclosure Date: August 30, 2022 (last updated February 24, 2025)
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
Attacker Value
Unknown

CVE-2022-26528

Disclosure Date: August 30, 2022 (last updated February 24, 2025)
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
Attacker Value
Unknown

CVE-2022-26527

Disclosure Date: August 30, 2022 (last updated February 24, 2025)
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
Attacker Value
Unknown

CVE-2022-25635

Disclosure Date: August 30, 2022 (last updated February 24, 2025)
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service.
Attacker Value
Unknown

CVE-2022-29558

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
Attacker Value
Unknown

CVE-2022-31574

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-27502

Disclosure Date: June 10, 2022 (last updated October 07, 2023)
RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM.
Attacker Value
Unknown

CVE-2022-1691

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
Attacker Value
Unknown

CVE-2022-27438

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.