Search Results (44126 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-43549 1 Qualcomm 278 Ar8035, Ar8035 Firmware, Csr8811 and 275 more 2025-01-10 8.4 High
Memory corruption while processing TPC target power table in FTM TPC.
CVE-2023-32181 1 Opensuse 1 Libeconf 2025-01-10 3.3 Low
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf allows for DoS via malformed configuration files This issue affects libeconf: before 0.5.2.
CVE-2023-29543 1 Mozilla 2 Firefox, Focus 2025-01-10 8.8 High
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVE-2023-29541 2 Mozilla, Redhat 9 Firefox, Firefox Esr, Focus and 6 more 2025-01-10 8.8 High
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
CVE-2018-5996 2 7-zip, Debian 3 7-zip, P7zip, Debian Linux 2025-01-10 N/A
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
CVE-2017-17969 2 7-zip, Debian 3 7-zip, P7zip, Debian Linux 2025-01-10 N/A
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
CVE-2023-2972 1 Antfu 1 Utils 2025-01-10 9.8 Critical
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
CVE-2023-24584 1 Gallagher 2 Controller 6000, Controller 6000 Firmware 2025-01-10 7.5 High
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior.
CVE-2024-54097 1 Huawei 2 Emui, Harmonyos 2025-01-10 7.3 High
Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.
CVE-2023-25731 1 Mozilla 1 Firefox 2025-01-10 8.8 High
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
CVE-2023-25730 2 Mozilla, Redhat 8 Firefox, Firefox Esr, Thunderbird and 5 more 2025-01-10 5.4 Medium
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
CVE-2023-25728 2 Mozilla, Redhat 8 Firefox, Firefox Esr, Thunderbird and 5 more 2025-01-10 6.5 Medium
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
CVE-2024-55663 1 Xwiki 1 Xwiki 2025-01-10 9.8 Critical
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can allow any user to inject HQL. Depending on the used database backend, the attacker may be able to not only obtain confidential information such as password hashes from the database, but also execute UPDATE/INSERT/DELETE queries. This has been patched in 13.10.5 and 14.3-rc-1. There is no known workaround, other than upgrading XWiki.
CVE-2023-43540 1 Qualcomm 58 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 55 more 2025-01-10 8.4 High
Memory corruption while processing the IOCTL FM HCI WRITE request.
CVE-2023-43539 1 Qualcomm 274 Ar8035, Ar8035 Firmware, Csr8811 and 271 more 2025-01-10 7.5 High
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
CVE-2023-33105 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Ar9380 and 295 more 2025-01-10 7.5 High
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
CVE-2023-33090 1 Qualcomm 104 Ar8035, Ar8035 Firmware, Fastconnect 6800 and 101 more 2025-01-10 5.5 Medium
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
CVE-2023-33078 1 Qualcomm 26 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 23 more 2025-01-10 5.1 Medium
Information Disclosure while processing IOCTL request in FastRPC.
CVE-2023-28582 1 Qualcomm 86 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 83 more 2025-01-10 9.8 Critical
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
CVE-2024-23366 1 Qualcomm 34 Qam8255p, Qam8255p Firmware, Qam8295p and 31 more 2025-01-10 6.6 Medium
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.