Show filters
1,213 Total Results
Displaying 41-50 of 1,213
Sort by:
Attacker Value
Unknown

CVE-2022-23824

Disclosure Date: November 08, 2022 (last updated February 04, 2024)
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
Attacker Value
Unknown

CVE-2020-14394

Disclosure Date: August 17, 2022 (last updated October 08, 2023)
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
Attacker Value
Unknown

CVE-2022-23825

Disclosure Date: July 12, 2022 (last updated November 08, 2023)
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
Attacker Value
Unknown

CVE-2022-29900

Disclosure Date: July 12, 2022 (last updated October 18, 2023)
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Attacker Value
Unknown

CVE-2021-42782

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
Attacker Value
Unknown

CVE-2021-42781

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
Attacker Value
Unknown

CVE-2021-42780

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
Attacker Value
Unknown

CVE-2021-42779

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
Attacker Value
Unknown

CVE-2021-42778

Disclosure Date: April 18, 2022 (last updated October 07, 2023)
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
Attacker Value
Unknown

CVE-2021-3618

Disclosure Date: March 23, 2022 (last updated November 29, 2024)
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.