6.7
CVE-2023-43526 - Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Audio
Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.
6.7
CVE-2023-43525 - Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Audio
Memory corruption while copying the sound model data from user to kernel buffer during sound model register.
6.7
CVE-2023-43524 - Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Audio
Memory corruption when the bandpass filter order received from AHAL is not within the expected range.
6.7
CVE-2023-43521 - Use After Free in HLOS
Memory corruption when multiple listeners are being registered with the same file descriptor.
8.4
CVE-2023-33119 - Time-of-check Time-of-use (TOCTOU) Race Condition in Hypervisor
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
7.5
CVE-2024-32972 - go-ethereum denial of service via malicious p2p message
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. The fix has been included in geth version `1.13.15โฆ
7.5
CVE-2024-4549 - Delta Electronics DIAEnergie SQL Injection
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
9.8
CVE-2024-4548 - Delta Electronics DIAEnergie SQL Injection
An SQLi vulnerability exists inย Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.
9.8
CVE-2024-4547 - Delta Electronics DIAEnergie Unauthenticated SQL Injection
A SQLi vulnerability exists inย Delta Electronicsย DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field
8.3
CVE-2024-3576 - NPort 5100A Series Store XSS Vulnerability
The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escโฆ