Show filters
440 Total Results
Displaying 181-190 of 440
Sort by:
Attacker Value
Unknown
CVE-2023-23301
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.
0
Attacker Value
Unknown
CVE-2023-23300
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.
0
Attacker Value
Unknown
CVE-2023-23299
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile information and GPS coordinates, among others.
0
Attacker Value
Unknown
CVE-2023-23298
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.
0
Attacker Value
Unknown
CVE-2022-47609
Disclosure Date: May 22, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Nicearma DNUI plugin <= 2.8.1 versions.
0
Attacker Value
Unknown
CVE-2023-31519
Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.
0
Attacker Value
Unknown
CVE-2023-22808
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
0
Attacker Value
Unknown
CVE-2022-46396
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
0
Attacker Value
Unknown
CVE-2023-26083
Disclosure Date: April 06, 2023 (last updated February 24, 2025)
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.
0
Attacker Value
Unknown
CVE-2022-46781
Disclosure Date: April 06, 2023 (last updated February 24, 2025)
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
0