All CVEs — page 238 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw is an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies, leading to potential buffer overflow and denial-of-service conditions. This matters because it can cause the web service process to crash upon exploitation.
The flaw allows untrusted input to be interpreted as a raster, potentially leading to file writing or network requests, which could result in remote code execution.
This vulnerability allows a remote attacker to execute arbitrary commands as root by exploiting multiple command injection flaws in the /api/esps request handler, leading to complete control of the affected device.
The flaw allows unauthenticated attackers to read arbitrary files and delete videos, posing a significant security risk.
The flaw allows remote code execution by executing unsandboxed Groovy scripts from database template fields, leading to arbitrary code execution and potential server compromise.
The flaw allows unauthenticated attackers to execute arbitrary code by exploiting an insecure deserialization vulnerability in the check_connection endpoint, leading to remote code execution with application process privileges.
The flaw involves memory corruption due to improper handling of untrusted user input in the fastboot command handler for audio framework configuration, which can lead to arbitrary code execution.
This flaw involves memory corruption due to invalid length values in Device Capability Extended attributes within NAN Service Discovery Frames, which could lead to remote code execution.
The flaw allows a transient Denial of Service (DoS) by processing an improperly sized wake time response frame, impacting Qualcomm and related firmware products.
The flaw allows attackers to exploit weak UE configuration checks, potentially leading to unauthorized access or data compromise without proper verification of security capabilities.
The flaw allows memory corruption when processing invalid IOCTL requests, potentially leading to arbitrary code execution.
The flaw involves memory corruption due to improper handling of malformed request parameters in the fingerprint TA, potentially leading to arbitrary code execution.
The flaw involves a cryptographic issue where malformed or missing authentication parameters can lead to unauthorized access during registration requests.
The flaw allows information disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling, potentially exposing sensitive data.
The flaw involves improper handling of length fields during wireless network channel switch processing, leading to potential information disclosure.
The flaw involves memory corruption when processing registry values with incorrect types using a direct query method, potentially leading to arbitrary code execution.
The flaw involves memory corruption due to improper handling of packet sizes near the maximum limit, potentially leading to arbitrary code execution.