Total
8217 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-45568 | 1 Qualcomm | 26 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 23 more | 2025-05-09 | N/A | 6.7 MEDIUM |
|
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
|
|||||
| CVE-2024-49846 | 1 Qualcomm | 62 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 59 more | 2025-05-09 | N/A | 8.2 HIGH |
|
Memory corruption while decoding of OTA messages from T3448 IE.
|
|||||
| CVE-2024-49847 | 1 Qualcomm | 94 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 91 more | 2025-05-09 | N/A | 7.5 HIGH |
|
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
|
|||||
| CVE-2022-25736 | 1 Qualcomm | 486 Aqt1000, Aqt1000 Firmware, Ar8031 and 483 more | 2025-05-09 | N/A | 7.5 HIGH |
|
Denial of service in WLAN due to out-of-bound read happens while processing VHT action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
|
|||||
| CVE-2022-25719 | 1 Qualcomm | 236 Apq8009, Apq8009 Firmware, Apq8009w and 233 more | 2025-05-09 | N/A | 8.2 HIGH |
|
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
|
|||||
| CVE-2022-43043 | 1 Gpac | 1 Gpac | 2025-05-09 | N/A | 5.5 MEDIUM |
|
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/field_decode.c.
|
|||||
| CVE-2022-43282 | 1 Webassembly | 1 Wabt | 2025-05-08 | N/A | 7.1 HIGH |
|
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.
|
|||||
| CVE-2024-21099 | 1 Oracle | 1 Business Intelligence | 2025-05-08 | N/A | 4.3 MEDIUM |
|
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visualization). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible dat ...
Show More |
|||||
| CVE-2022-3599 | 3 Debian, Libtiff, Netapp | 3 Debian Linux, Libtiff, Active Iq Unified Manager | 2025-05-07 | N/A | 5.5 MEDIUM |
|
LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
|
|||||
| CVE-2025-29913 | 1 Nasa | 1 Cryptolib | 2025-05-07 | N/A | 9.8 CRITICAL |
|
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability was identified in the `Crypto_TC_Prep_AAD` function of CryptoLib versions 1.3.3 and prior. This vulnerability allows an attacker to trigger a Denial of Service (DoS) or potentially execute arbitrary code (RCE) by providing ...
Show More |
|||||
| CVE-2025-21530 | 1 Oracle | 1 Peoplesoft Enterprise Peopletools | 2025-05-07 | N/A | 4.3 MEDIUM |
|
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiali ...
Show More |
|||||
| CVE-2024-11596 | 1 Wireshark | 1 Wireshark | 2025-05-07 | N/A | 7.8 HIGH |
|
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
|
|||||
| CVE-2022-39836 | 1 Genivi | 1 Diagnostic Log And Trace | 2025-05-07 | N/A | 5.5 MEDIUM |
|
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.
|
|||||
| CVE-2022-43280 | 1 Webassembly | 1 Wabt | 2025-05-07 | N/A | 7.1 HIGH |
|
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
|
|||||
| CVE-2025-1400 | 2025-05-07 | N/A | 3.1 LOW | ||
|
Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.
|
|||||
| CVE-2025-1399 | 2025-05-07 | N/A | 3.1 LOW | ||
|
Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.
|
|||||
| CVE-2024-23533 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 6.5 MEDIUM |
|
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
|
|||||
| CVE-2024-23532 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 7.5 HIGH |
|
An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.
|
|||||
| CVE-2022-44081 | 1 Lodev | 1 Lodepng | 2025-05-06 | N/A | 5.5 MEDIUM |
|
Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.
|
|||||
| CVE-2022-32936 | 1 Apple | 1 Macos | 2025-05-06 | N/A | 5.5 MEDIUM |
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose kernel memory.
|
|||||
| CVE-2018-6340 | 1 Facebook | 1 Hhvm | 2025-05-06 | 6.8 MEDIUM | 8.1 HIGH |
|
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
|
|||||
| CVE-2024-23530 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 7.5 HIGH |
|
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
|
|||||
| CVE-2024-23529 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 7.5 HIGH |
|
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
|
|||||
| CVE-2024-23528 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 7.5 HIGH |
|
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
|
|||||
| CVE-2024-23526 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 7.5 HIGH |
|
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
|
|||||
| CVE-2018-20618 | 1 Ok-file-formats Project | 1 Ok-file-formats | 2025-05-06 | 6.8 MEDIUM | 8.8 HIGH |
|
ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
|
|||||
| CVE-2024-23527 | 1 Ivanti | 1 Avalanche | 2025-05-06 | N/A | 7.5 HIGH |
|
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
|
|||||
| CVE-2022-43359 | 1 Gifdec Project | 1 Gifdec | 2025-05-05 | N/A | 7.8 HIGH |
|
Gifdec commit 1dcbae19363597314f6623010cc80abad4e47f7c was discovered to contain an out-of-bounds read in the function read_image_data. This vulnerability is triggered when parsing a crafted Gif file.
|
|||||
| CVE-2024-35385 | 1 Cesanta | 1 Mjs | 2025-05-05 | N/A | 4.3 MEDIUM |
|
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.
|
|||||
| CVE-2022-21730 | 1 Google | 1 Tensorflow | 2025-05-05 | 5.5 MEDIUM | 8.1 HIGH |
|
Tensorflow is an Open Source Machine Learning Framework. The implementation of `FractionalAvgPoolGrad` does not consider cases where the input tensors are invalid allowing an attacker to read from outside of bounds of heap. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.
|
|||||
| CVE-2022-21728 | 1 Google | 1 Tensorflow | 2025-05-05 | 5.5 MEDIUM | 8.1 HIGH |
|
Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ReverseSequence` does not fully validate the value of `batch_dim` and can result in a heap OOB read. There is a check to make sure the value of `batch_dim` does not go over the rank of the input, but there is no check for negative values. Negative dimensions are allowed in some cases to mimic Python's negative indexing (i.e., indexing from the end of the array), however if the value is too negativ ...
Show More |
|||||
| CVE-2022-21726 | 1 Google | 1 Tensorflow | 2025-05-05 | 6.5 MEDIUM | 8.1 HIGH |
|
Tensorflow is an Open Source Machine Learning Framework. The implementation of `Dequantize` does not fully validate the value of `axis` and can result in heap OOB accesses. The `axis` argument can be `-1` (the default value for the optional argument) or any other positive value at most the number of dimensions of the input. Unfortunately, the upper bound is not checked and this results in reading past the end of the array containing the dimensions of the input tensor. The fix will be included in ...
Show More |
|||||
| CVE-2022-21240 | 1 Intel | 6 Proset Wi-fi 6e Ax210, Proset Wi-fi 6e Ax210 Firmware, Wi-fi 6e Ax211 and 3 more | 2025-05-05 | N/A | 4.4 MEDIUM |
|
Out of bounds read for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable information disclosure via local access.
|
|||||
| CVE-2022-21226 | 1 Intel | 1 Trace Analyzer And Collector | 2025-05-05 | 2.1 LOW | 5.5 MEDIUM |
|
Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable information disclosure via local access.
|
|||||
| CVE-2022-21133 | 1 Intel | 1 Trace Analyzer And Collector | 2025-05-05 | 2.1 LOW | 5.5 MEDIUM |
|
Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.
|
|||||
| CVE-2021-33120 | 1 Intel | 50 Atom P5921b, Atom P5921b Firmware, Atom P5931b and 47 more | 2025-05-05 | 5.5 MEDIUM | 5.4 MEDIUM |
|
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
|
|||||
| CVE-2021-33105 | 1 Intel | 4 Core I5-8305g, Core I5-8305g Firmware, Core I7-8706g and 1 more | 2025-05-05 | 2.1 LOW | 5.5 MEDIUM |
|
Out-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an authenticated user to potentially enable information disclosure via local access.
|
|||||
| CVE-2021-31239 | 1 Sqlite | 1 Sqlite | 2025-05-05 | N/A | 7.5 HIGH |
|
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
|
|||||
| CVE-2021-26950 | 1 Intel | 36 Dual Band Wireless-ac 3165, Dual Band Wireless-ac 3165 Firmware, Dual Band Wireless-ac 3168 and 33 more | 2025-05-05 | N/A | 5.5 MEDIUM |
|
Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.
|
|||||
| CVE-2021-26254 | 1 Intel | 18 Killer Ac 1550, Killer Ac 1550 Firmware, Killer Wi-fi 6 Ax1650 and 15 more | 2025-05-05 | N/A | 5.5 MEDIUM |
|
Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denial of service via local access.
|
|||||