Show filters
1,441 Total Results
Displaying 31-40 of 1,441
Sort by:
Attacker Value
Unknown

CVE-2015-7547

Disclosure Date: February 18, 2016 (last updated November 25, 2024)
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
1
Attacker Value
Unknown

CVE-2025-1507

Disclosure Date: March 14, 2025 (last updated March 14, 2025)
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() function in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to disable all features.
Attacker Value
Unknown

CVE-2024-13321

Disclosure Date: March 14, 2025 (last updated March 14, 2025)
The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to, and including, 2.0.0 due to insufficient authorization checks on the handle_get_stats() function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2024-9157

Disclosure Date: March 11, 2025 (last updated March 12, 2025)
** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record’s reference information.
0
Attacker Value
Unknown

CVE-2024-53024

Disclosure Date: March 03, 2025 (last updated March 07, 2025)
Memory corruption in display driver while detaching a device.
Attacker Value
Unknown

CVE-2024-53014

Disclosure Date: March 03, 2025 (last updated March 07, 2025)
Memory corruption may occur while validating ports and channels in Audio driver.
Attacker Value
Unknown

CVE-2024-43056

Disclosure Date: March 03, 2025 (last updated March 07, 2025)
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
Attacker Value
Unknown

CVE-2024-43051

Disclosure Date: March 03, 2025 (last updated March 07, 2025)
Information disclosure while deriving keys for a session for any Widevine use case.
Attacker Value
Unknown

CVE-2024-38426

Disclosure Date: March 03, 2025 (last updated March 07, 2025)
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Attacker Value
Unknown

CVE-2025-0895

Disclosure Date: March 02, 2025 (last updated March 03, 2025)
IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages.