Show filters
360 Total Results
Displaying 1-10 of 360
Sort by:
Attacker Value
Moderate

OpenSSL TLS Server Crash (NULL pointer dereference) — CVE-2021-3449

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Attacker Value
Unknown

CVE-2024-38420

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while configuring a Hypervisor based input virtual device.
Attacker Value
Unknown

CVE-2024-33056

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Attacker Value
Unknown

CVE-2024-33044

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Attacker Value
Unknown

CVE-2024-38408

Disclosure Date: November 04, 2024 (last updated November 09, 2024)
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Attacker Value
Unknown

CVE-2024-23369

Disclosure Date: October 07, 2024 (last updated October 17, 2024)
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
Attacker Value
Unknown

CVE-2024-33051

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Attacker Value
Unknown

CVE-2024-23357

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Attacker Value
Unknown

CVE-2024-23356

Disclosure Date: August 05, 2024 (last updated December 21, 2024)
Memory corruption during session sign renewal request calls in HLOS.
Attacker Value
Unknown

CVE-2024-23355

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Memory corruption when keymaster operation imports a shared key.