Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-33277 | 1 Qualcomm | 486 Aqt1000, Aqt1000 Firmware, Ar8031 and 483 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. | |||||
CVE-2022-33271 | 1 Qualcomm | 490 Apq8096au, Apq8096au Firmware, Aqt1000 and 487 more | 2023-02-21 | N/A | 7.5 HIGH |
Information disclosure due to buffer over-read in WLAN while parsing NMF frame. | |||||
CVE-2022-33248 | 1 Qualcomm | 324 Apq8009, Apq8009 Firmware, Apq8009w and 321 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. | |||||
CVE-2022-33246 | 1 Qualcomm | 84 Apq8096au, Apq8096au Firmware, Aqt1000 and 81 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id. | |||||
CVE-2022-33243 | 1 Qualcomm | 314 Apq8096au, Apq8096au Firmware, Aqt1000 and 311 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption due to improper access control in Qualcomm IPC. | |||||
CVE-2022-33233 | 1 Qualcomm | 402 Apq8009, Apq8009 Firmware, Apq8009w and 399 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption due to configuration weakness in modem wile sending command to write protected files. | |||||
CVE-2022-33232 | 1 Qualcomm | 222 Aqt1000, Aqt1000 Firmware, Ar8035 and 219 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory. | |||||
CVE-2023-0781 | 1 Canteen Management System Project | 1 Canteen Management System | 2023-02-21 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulnerability affects the function query of the file removeOrder.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220624. | |||||
CVE-2022-33229 | 1 Qualcomm | 42 Ar8031, Ar8031 Firmware, Csra6620 and 39 more | 2023-02-21 | N/A | 7.5 HIGH |
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. | |||||
CVE-2022-33225 | 1 Qualcomm | 58 Apq8096au, Apq8096au Firmware, Mdm9628 and 55 more | 2023-02-21 | N/A | 7.8 HIGH |
Memory corruption due to use after free in trusted application environment. | |||||
CVE-2022-33221 | 1 Qualcomm | 28 Sd 8 Gen1 5g, Sd 8 Gen1 5g Firmware, Ssg2115p and 25 more | 2023-02-21 | N/A | 5.5 MEDIUM |
Information disclosure in Trusted Execution Environment due to buffer over-read while processing metadata verification requests. | |||||
CVE-2022-33216 | 1 Qualcomm | 36 Qam8295p, Qam8295p Firmware, Qca6574a and 33 more | 2023-02-21 | N/A | 5.5 MEDIUM |
Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file. | |||||
CVE-2022-25738 | 1 Qualcomm | 70 Ar8031, Ar8031 Firmware, Csra6620 and 67 more | 2023-02-21 | N/A | 7.5 HIGH |
Information disclosure in modem due to buffer over-red while performing checksum of packet received | |||||
CVE-2023-21436 | 1 Samsung | 1 Android | 2023-02-21 | N/A | 3.3 LOW |
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID. | |||||
CVE-2022-25735 | 1 Qualcomm | 68 Ar8031, Ar8031 Firmware, Csra6620 and 65 more | 2023-02-21 | N/A | 7.5 HIGH |
Denial of service in modem due to missing null check while processing TCP or UDP packets from server | |||||
CVE-2022-25734 | 1 Qualcomm | 70 Ar8031, Ar8031 Firmware, Csra6620 and 67 more | 2023-02-21 | N/A | 7.5 HIGH |
Denial of service in modem due to missing null check while processing IP packets with padding | |||||
CVE-2022-25733 | 1 Qualcomm | 70 Ar8031, Ar8031 Firmware, Csra6620 and 67 more | 2023-02-21 | N/A | 7.5 HIGH |
Denial of service in modem due to null pointer dereference while processing DNS packets | |||||
CVE-2022-3171 | 2 Fedoraproject, Google | 6 Fedora, Google-protobuf, Protobuf-java and 3 more | 2023-02-21 | N/A | 7.5 HIGH |
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. | |||||
CVE-2022-34384 | 1 Dell | 5 Alienware Update, Command Update, Supportassist For Business Pcs and 2 more | 2023-02-21 | N/A | 7.8 HIGH |
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. | |||||
CVE-2022-34386 | 1 Dell | 2 Supportassist For Business Pcs, Supportassist For Home Pcs | 2023-02-21 | N/A | 5.5 MEDIUM |
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. |