All CVEs — page 38 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw is an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies, leading to potential buffer overflow and denial-of-service conditions. This matters because it can cause the web service process to crash upon exploitation.
The flaw allows untrusted input to be used in spatial lookups, potentially leading to file writes and network requests that could result in remote code execution.
The flaw allows command injection via the /api/esps request handler, enabling remote attackers to execute arbitrary commands as root.
The flaw allows unauthenticated attackers to read sensitive files and delete videos, posing a significant security risk.
The flaw allows remote code execution by unsandboxed Groovy scripts from database template fields, enabling attackers to execute arbitrary commands on the backend server.
The flaw allows unauthenticated attackers to execute arbitrary code by deserializing crafted YAML/JSON input, posing a significant security risk.
The flaw involves memory corruption due to improper handling of untrusted user input in the fastboot command handler for audio framework configuration, which can lead to arbitrary code execution.
The flaw involves memory corruption when processing Device Capability Extended attributes in specific NAN Service Discovery Frames with invalid length values, potentially leading to remote code execution.
The flaw allows a transient Denial of Service (DoS) by processing an improperly sized wake time response frame, impacting Qualcomm and related firmware products.
The flaw allows attackers to exploit weak UE configuration checks, potentially leading to unauthorized access or data compromise without proper verification of security capabilities.
The flaw allows memory corruption when processing invalid IOCTL requests, potentially leading to arbitrary code execution.
The flaw involves memory corruption due to improper handling of malformed request parameters in the fingerprint TA, potentially leading to arbitrary code execution.
The flaw involves a cryptographic issue where malformed or missing authentication parameters can lead to unauthorized access during registration requests.
The flaw allows information disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling, potentially exposing sensitive data.
The flaw involves improper handling of length fields during wireless network channel switch processing, leading to potential information disclosure.
The flaw involves memory corruption when processing registry values with incorrect types using a direct query method, potentially leading to arbitrary code execution.
The flaw involves memory corruption due to improper handling of packet sizes near the maximum limit, potentially leading to arbitrary code execution.