Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-0288 | 1 Openssl | 1 Openssl | 2022-12-13 | 5.0 MEDIUM | N/A |
The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) via an invalid certificate key. | |||||
CVE-2015-0291 | 1 Openssl | 1 Openssl | 2022-12-13 | 5.0 MEDIUM | N/A |
The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_algorithms extension in the ClientHello message during a renegotiation. | |||||
CVE-2015-0207 | 1 Openssl | 1 Openssl | 2022-12-13 | 5.0 MEDIUM | N/A |
The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to cause a denial of service (application crash) via crafted DTLS traffic, as demonstrated by DTLS 1.0 traffic to a DTLS 1.2 server. | |||||
CVE-2015-0208 | 1 Openssl | 1 Openssl | 2022-12-13 | 4.3 MEDIUM | N/A |
The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted RSA PSS parameters to an endpoint that uses the certificate-verification feature. | |||||
CVE-2022-37918 | 1 Arubanetworks | 1 Airwave | 2022-12-12 | N/A | 8.1 HIGH |
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below. | |||||
CVE-2022-37917 | 1 Arubanetworks | 1 Airwave | 2022-12-12 | N/A | 8.1 HIGH |
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below. | |||||
CVE-2022-37916 | 1 Arubanetworks | 1 Airwave | 2022-12-12 | N/A | 8.1 HIGH |
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below. | |||||
CVE-2022-39898 | 1 Google | 1 Android | 2022-12-12 | N/A | 3.3 LOW |
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim. | |||||
CVE-2022-39900 | 1 Google | 1 Android | 2022-12-12 | N/A | 4.6 MEDIUM |
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch. | |||||
CVE-2022-44938 | 1 Seeddms | 1 Seeddms | 2022-12-12 | N/A | 9.8 CRITICAL |
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack. | |||||
CVE-2022-39915 | 2 Google, Samsung | 2 Android, Calendar | 2022-12-12 | N/A | 5.5 MEDIUM |
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent. | |||||
CVE-2022-39911 | 1 Samsung | 1 Pass | 2022-12-12 | N/A | 6.8 MEDIUM |
Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass. | |||||
CVE-2022-39910 | 1 Samsung | 1 Pass | 2022-12-12 | N/A | 4.2 MEDIUM |
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view. | |||||
CVE-2022-39906 | 1 Google | 1 Android | 2022-12-12 | N/A | 3.3 LOW |
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information. | |||||
CVE-2022-45910 | 1 Apache | 1 Manifoldcf | 2022-12-12 | N/A | 5.3 MEDIUM |
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions. | |||||
CVE-2022-39905 | 1 Google | 1 Android | 2022-12-09 | N/A | 5.5 MEDIUM |
Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent. | |||||
CVE-2022-44932 | 1 Tenda | 2 A18, A18 Firmware | 2022-12-09 | N/A | 7.5 HIGH |
An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service. | |||||
CVE-2022-39894 | 1 Google | 1 Android | 2022-12-09 | N/A | 3.3 LOW |
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent. | |||||
CVE-2022-39895 | 1 Google | 1 Android | 2022-12-09 | N/A | 3.3 LOW |
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent. | |||||
CVE-2022-39896 | 1 Google | 1 Android | 2022-12-09 | N/A | 3.3 LOW |
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent. |