Show filters
718 Total Results
Displaying 91-100 of 718
Sort by:
Attacker Value
Unknown

CVE-2024-23369

Disclosure Date: October 07, 2024 (last updated October 17, 2024)
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Attacker Value
Unknown

CVE-2024-21455

Disclosure Date: October 07, 2024 (last updated October 17, 2024)
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
Attacker Value
Unknown

CVE-2023-27584

Disclosure Date: September 19, 2024 (last updated December 21, 2024)
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2024-45280

Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
0
Attacker Value
Unknown

CVE-2024-38402

Disclosure Date: September 02, 2024 (last updated September 06, 2024)
Memory corruption while processing IOCTL call for getting group info.
Attacker Value
Unknown

CVE-2024-38401

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption while processing concurrent IOCTL calls.
Attacker Value
Unknown

CVE-2024-33060

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when two threads try to map and unmap a single node simultaneously.
Attacker Value
Unknown

CVE-2024-33057

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
Attacker Value
Unknown

CVE-2024-33054

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.
Attacker Value
Unknown

CVE-2024-33052

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when user provides data for FM HCI command control operations.