Search Results (579 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-46724 2 Redhat, Squid-cache 6 Enterprise Linux, Rhel Aus, Rhel E4s and 3 more 2025-02-13 8.6 High
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.
CVE-2024-27179 1 Toshibatec 40 E-studio-2010-ac, E-studio-2015-nc, E-studio-2020 Ac and 37 more 2025-02-13 4.7 Medium
Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.
CVE-2024-22181 1 Libigl 1 Libigl 2025-02-13 7.8 High
An out-of-bounds write vulnerability exists in the readNODE functionality of libigl v2.5.0. A specially crafted .node file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2023-6298 1 Itextpdf 1 Itext 2025-02-13 4.3 Medium
A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of this vulnerability is VDB-246124. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. A statement published afterwards explains that the exception is not a vulnerability and the identified CWEs might not apply to the software.
CVE-2023-35126 1 Justsystems 19 Easy Postcard Max, Ichitaro 2021, Ichitaro 2022 and 16 more 2025-02-13 7.8 High
An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause memory corruption, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-27597 1 Qnap 18 Qts, Quts Hero, Qutscloud and 15 more 2025-02-12 2.7 Low
A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later
CVE-2023-26066 1 Lexmark 217 6500e, B2236, B2338 and 214 more 2025-02-11 9.8 Critical
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
CVE-2022-38072 2 Admesh Project, Slic3r 2 Admesh, Libslic3r 2025-02-11 6.5 Medium
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2024-49843 1 Qualcomm 104 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 7800 and 101 more 2025-02-05 7.8 High
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
CVE-2024-49834 1 Qualcomm 254 Csra6620, Csra6620 Firmware, Csra6640 and 251 more 2025-02-05 7.8 High
Memory corruption while power-up or power-down sequence of the camera sensor.
CVE-2024-45582 1 Qualcomm 68 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 65 more 2025-02-05 7.8 High
Memory corruption while validating number of devices in Camera kernel .
CVE-2024-49832 1 Qualcomm 50 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 47 more 2025-02-05 7.8 High
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
CVE-2024-49833 1 Qualcomm 160 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 157 more 2025-02-05 7.8 High
Memory corruption can occur in the camera when an invalid CID is used.
CVE-2025-20643 2 Google, Mediatek 44 Android, Mt6739, Mt6761 and 41 more 2025-02-04 5.7 Medium
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.
CVE-2023-0755 3 Ge, Ptc, Rockwellautomation 9 Digital Industrial Gateway Server, Kepware Server, Kepware Serverex and 6 more 2025-01-16 9.8 Critical
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
CVE-2023-4215 1 Advantech 1 Webaccess 2025-01-16 6.5 Medium
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
CVE-2024-45550 1 Qualcomm 16 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 13 more 2025-01-13 7.8 High
Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.
CVE-2023-31307 1 Amd 32 Radeon Pro W6300, Radeon Pro W6400, Radeon Pro W6600 and 29 more 2024-12-13 2.3 Low
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
CVE-2024-33044 1 Qualcomm 425 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 422 more 2024-12-12 8.4 High
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-5680 1 Schneider-electric 1 Ecostruxure Foxboro Dcs Control Core Services 2024-11-21 7.1 High
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.