Show filters
141 Total Results
Displaying 1-10 of 141
Sort by:
Attacker Value
Moderate

OpenSSL TLS Server Crash (NULL pointer dereference) — CVE-2021-3449

Disclosure Date: March 25, 2021 (last updated November 08, 2023)
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Attacker Value
Unknown

CVE-2024-33056

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Attacker Value
Unknown

CVE-2024-33044

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Attacker Value
Unknown

CVE-2024-38408

Disclosure Date: November 04, 2024 (last updated November 09, 2024)
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Attacker Value
Unknown

CVE-2024-33051

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Attacker Value
Unknown

CVE-2024-23353

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
Attacker Value
Unknown

CVE-2024-21481

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
Attacker Value
Unknown

CVE-2023-43536

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
Transient DOS while parse fils IE with length equal to 1.
Attacker Value
Unknown

CVE-2023-43533

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Attacker Value
Unknown

CVE-2023-43522

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.