Show filters
155 Total Results
Displaying 91-100 of 155
Sort by:
Attacker Value
Unknown
CVE-2022-44455
Disclosure Date: December 08, 2022 (last updated February 24, 2025)
The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.
0
Attacker Value
Unknown
CVE-2022-41802
Disclosure Date: December 08, 2022 (last updated February 24, 2025)
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
0
Attacker Value
Unknown
CVE-2022-41686
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.
0
Attacker Value
Unknown
CVE-2022-38701
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
0
Attacker Value
Unknown
CVE-2022-36423
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.
0
Attacker Value
Unknown
CVE-2022-33156
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
0
Attacker Value
Unknown
CVE-2021-35283
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.
0
Attacker Value
Unknown
CVE-2022-0388
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2020-35216
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages.
0
Attacker Value
Unknown
CVE-2020-35215
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.
0