Show filters
440 Total Results
Displaying 171-180 of 440
Sort by:
Attacker Value
Unknown
CVE-2023-33477
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.
0
Attacker Value
Unknown
CVE-2023-28469
Disclosure Date: June 02, 2023 (last updated February 25, 2025)
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.
0
Attacker Value
Unknown
CVE-2023-28147
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.
0
Attacker Value
Unknown
CVE-2023-2065
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .
0
Attacker Value
Unknown
CVE-2023-31763
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
0
Attacker Value
Unknown
CVE-2023-23306
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary memory and hijack the execution of the device's firmware.
0
Attacker Value
Unknown
CVE-2023-23305
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware.
0
Attacker Value
Unknown
CVE-2023-23304
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module without the user's consent and disclose potentially private or sensitive information.
0
Attacker Value
Unknown
CVE-2023-23303
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.
0
Attacker Value
Unknown
CVE-2023-23302
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.
0