| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack. |
| IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236069. |
| IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack. This results in the restore operation gaining access to files which the operator should not have access to. IBM X-Force ID: 235873. |
| Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel. |
| Memory corruption in Automotive Android OS due to improper validation of array index. |
| Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network. |
| Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response. |
| Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. |
| Transient DOS due to buffer over-read in WLAN while sending a packet to device. |
| Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. |
| Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. |
| Memory corruption due to improper access control in kernel while processing a mapping request from root process. |
| Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM. |
| Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis. |
| Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service. |
| Information disclosure in Kernel due to indirect branch misprediction. |
| Memory corruption in Linux Networking due to double free while handling a hyp-assign. |
| Transient DOS due to improper authorization in Modem |