6.6
CVE-2024-45540 - Use After Free in HLOS
Memory corruption while invoking IOCTL map buffer request from userspace.
7.8
CVE-2024-43067 - Time-of-check Time-of-use (TOCTOU) Race Condition in Camera
Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.
7.8
CVE-2024-43066 - Use After Free in HLOS
Memory corruption while handling file descriptor during listener registration/de-registration.
7.1
CVE-2024-43065 - Exposed Dangerous Method or Function in HLOS
Cryptographic issues while generating an asymmetric key pair for RKP use cases.
7.8
CVE-2024-43058 - Incorrect Type Conversion or Cast in Multimedia Frameworks
Memory corruption while processing IOCTL calls.
5.5
CVE-2024-43046 - Information Exposure in TZ Secure OS
There may be information disclosure during memory re-allocation in TZ Secure OS.
7.5
CVE-2024-33058 - Insufficient Granularity of Access Control in Core
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
5.3
CVE-2025-3347 - code-projects Patient Record Management System dental_pending.php sql injection
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_pending.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has beenβ¦
8.7
CVE-2025-3346 - Tenda AC7 SetPptpServerCfg formSetPPTPServer buffer overflow
A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip leads to buffer overflow. The attack may be launβ¦
6.9
CVE-2025-3345 - codeprojects Online Restaurant Management System combo.php sql injection
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql injection. The attack can be launched remotβ¦