Show filters
526 Total Results
Displaying 21-30 of 526
Sort by:
Attacker Value
Unknown

CVE-2024-33037

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
Attacker Value
Unknown

CVE-2024-33036

Disclosure Date: December 02, 2024 (last updated February 27, 2025)
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
Attacker Value
Unknown

CVE-2024-38423

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while processing GPU page table switch.
Attacker Value
Unknown

CVE-2024-38422

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Attacker Value
Unknown

CVE-2024-38415

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption while handling session errors from firmware.
Attacker Value
Unknown

CVE-2024-38408

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Attacker Value
Unknown

CVE-2024-33032

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-23369

Disclosure Date: October 07, 2024 (last updated February 26, 2025)
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Attacker Value
Unknown

CVE-2024-9118

Disclosure Date: October 01, 2024 (last updated February 26, 2025)
The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0