Filtered by vendor Tencent Subscriptions
Total 25 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-27247 1 Tencent 1 Wechat 2024-08-03 6.5 Medium
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat 2.9.5 desktop version. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM decoder. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-11907.
CVE-2022-35158 1 Tencent 1 Tscancode 2024-08-03 7.5 High
A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.
CVE-2023-34312 1 Tencent 2 Qq, Tim 2024-08-02 7.8 High
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
CVE-2023-30363 1 Tencent 1 Vconsole 2024-08-02 9.8 Critical
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
CVE-2024-40433 1 Tencent 1 Wechat 2024-08-02 8.8 High
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.