Latest CVE Feed
-
7.8
HIGHCVE-2024-53104
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calcul... Read more
Affected Products : linux_kernel- Actively Exploited
- Published: Dec. 02, 2024
- Modified: Feb. 06, 2025
-
7.8
HIGHCVE-2024-53103
In the Linux kernel, the following vulnerability has been resolved: hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer When hvs is released, there is a possibility that vsk->trans may not be initialized to NULL, which could lead to a... Read more
Affected Products : linux_kernel- Published: Dec. 02, 2024
- Modified: Jan. 07, 2025
-
6.5
MEDIUMCVE-2024-20139
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Pat... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 02, 2024
-
7.5
HIGHCVE-2024-20138
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0899829... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2024-20137
In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 02, 2024
-
6.2
MEDIUMCVE-2024-20136
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID:... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20135
In soundtrigger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09142526; Issu... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20134
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09154589; Issue ID: MSV... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20133
In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issu... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20132
In Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00957388; Issue... Read more
- Published: Dec. 02, 2024
- Modified: Jun. 25, 2025
-
6.7
MEDIUMCVE-2024-20131
In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issu... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20130
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09193374; Issue ID: M... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2024-20129
In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ... Read more
- Published: Dec. 02, 2024
- Modified: Mar. 13, 2025
-
7.5
HIGHCVE-2024-20128
In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
7.5
HIGHCVE-2024-20127
In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20125
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained System privileges. User interaction is not needed for exploitation. Patch ID: ALPS09... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
4.4
MEDIUMCVE-2024-20116
In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
3.7
LOWCVE-2024-11856
A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 02, 2024
-
7.5
HIGHCVE-2024-53605
Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-12007
A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part of the file /visualizar-produto.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack... Read more
- Published: Dec. 01, 2024
- Modified: Dec. 11, 2024