| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 4.3.6.2441 build 20230621 and later
QTS 4.3.3.2420 build 20230621 and later
QTS 4.2.6 build 20230621 and later
QTS 4.3.4.2451 build 20230621 and later
|
| IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368. |
| An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. |
| Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
|
| Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access. |
|
A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group.
This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)
|
| After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address. |
| Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard. |
| Transient DOS while parsing WLAN beacon or probe-response frame. |
| Transient DOS in WLAN Firmware while parsing FT Information Elements. |
| Transient DOS in WLAN Firmware while processing frames with missing header fields. |
| Transient DOS in WLAN Firmware while processing the received beacon or probe response frame. |
| Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length. |
| Memory corruption in WLAN while running doDriverCmd for an unspecific command. |
| Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client. |
| Memory Corruption due to improper validation of array index in Linux while updating adn record. |
| Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony. |
| Memory corruption in Automotive GPU while querying a gsl memory node. |
| Information disclosure in Network Services due to buffer over-read while the device receives DNS response. |