Latest CVE Feed
-
7.8
HIGHCVE-2025-22040
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race condition between session setup and ksmbd_sessions_deregister. The session can be freed before the connectio... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2025-22041
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can occur in session_deregister when the second channel sets up a session through the connection... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-22085
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use-after-free when rename device name Syzbot reported a slab-use-after-free with the following call trace: =============================================================... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-22088
In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() After the erdma_cep_put(new_cep) being called, new_cep will be freed, and the following dereference will cause a UAF problem... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-22097
In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix use after free and double free on init error If the driver initialization fails, the vkms_exit() function might access an uninitialized or freed default_config pointer and... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption
-
4.0
MEDIUMCVE-2024-20065
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0869... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-20067
In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267285; Issu... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
5.9
MEDIUMCVE-2024-20068
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01270721; Issue ID: MSV-... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
6.5
MEDIUMCVE-2024-20069
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
5.1
MEDIUMCVE-2024-20070
In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execu... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
4.4
MEDIUMCVE-2024-20071
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Iss... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
6.6
MEDIUMCVE-2024-20072
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; I... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
6.6
MEDIUMCVE-2024-20073
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; ... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
6.6
MEDIUMCVE-2024-20074
In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08668110; Issue ID: MSV... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 25, 2025
-
6.7
MEDIUMCVE-2024-20090
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MS... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025
-
7.8
HIGHCVE-2024-20092
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MS... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2024-20094
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-15... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025
-
6.7
MEDIUMCVE-2024-20098
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: M... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025
-
6.7
MEDIUMCVE-2024-20099
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: M... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-20100
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Iss... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025