Show filters
1,321 Total Results
Displaying 1-10 of 1,321
Sort by:
Attacker Value
Very High

CVE-2014-6271

Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Attacker Value
Unknown

CVE-2024-49839

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption during management frame processing due to mismatch in T2LM info element.
Attacker Value
Unknown

CVE-2024-49838

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Information disclosure while parsing the OCI IE with invalid length.
Attacker Value
Unknown

CVE-2024-45571

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
Attacker Value
Unknown

CVE-2024-45569

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while parsing the ML IE due to invalid frame content.
Attacker Value
Unknown

CVE-2024-38420

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while configuring a Hypervisor based input virtual device.
Attacker Value
Unknown

CVE-2024-38418

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while parsing the memory map info in IOCTL calls.
Attacker Value
Unknown

CVE-2024-38416

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Information disclosure during audio playback.
Attacker Value
Unknown

CVE-2024-38404

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
Attacker Value
Unknown

CVE-2024-45558

Disclosure Date: January 06, 2025 (last updated January 14, 2025)
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.