Show filters
90 Total Results
Displaying 21-30 of 90
Sort by:
Attacker Value
Unknown

CVE-2023-20843

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119.
Attacker Value
Unknown

CVE-2023-20842

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477.
Attacker Value
Unknown

CVE-2023-20841

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326441.
Attacker Value
Unknown

CVE-2023-20840

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430.
Attacker Value
Unknown

CVE-2023-20839

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.
Attacker Value
Unknown

CVE-2023-20835

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07326570.
Attacker Value
Unknown

CVE-2022-32666

Disclosure Date: July 04, 2023 (last updated October 08, 2023)
In Wi-Fi, there is a possible low throughput due to misrepresentation of critical information. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220829014; Issue ID: GN20220829014.
Attacker Value
Unknown

CVE-2023-0605

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2022-32659

Disclosure Date: January 03, 2023 (last updated October 08, 2023)
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705066; Issue ID: GN20220705066.
Attacker Value
Unknown

CVE-2022-28201

Disclosure Date: September 19, 2022 (last updated November 29, 2024)
An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.