Show filters
718 Total Results
Displaying 141-150 of 718
Sort by:
Attacker Value
Unknown

CVE-2024-23353

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
Attacker Value
Unknown

CVE-2024-23352

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
Attacker Value
Unknown

CVE-2024-23350

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
Attacker Value
Unknown

CVE-2024-21481

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
Attacker Value
Unknown

CVE-2024-21479

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Transient DOS during music playback of ALAC content.
Attacker Value
Unknown

CVE-2024-21467

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Information disclosure while handling beacon probe frame during scan entry generation in client side.
Attacker Value
Unknown

CVE-2024-21459

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Information disclosure while handling beacon or probe response frame in STA.
Attacker Value
Unknown

CVE-2023-40702

Disclosure Date: July 09, 2024 (last updated July 10, 2024)
PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication from the user's existing registered devices. A threat actor might be able to exploit this vulnerability to authenticate as a target user if they have existing knowledge of the target user’s first-factor credentials.
0
Attacker Value
Unknown

CVE-2023-40356

Disclosure Date: July 09, 2024 (last updated July 10, 2024)
PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered devices. A threat actor might be able to exploit this vulnerability to register their own MFA device with a target user’s account if they have existing knowledge of the target user’s first factor credential.
0
Attacker Value
Unknown

CVE-2024-23380

Disclosure Date: July 01, 2024 (last updated July 03, 2024)
Memory corruption while handling user packets during VBO bind operation.