| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Azure Sphere Elevation of Privilege Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Information Disclosure Vulnerability |
| Azure Sphere Elevation of Privilege Vulnerability |
| Azure Sphere Elevation of Privilege Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Denial of Service Vulnerability |
| Azure Sphere Information Disclosure Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Tampering Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Elevation of Privilege Vulnerability |
| Microsoft SharePoint Information Disclosure Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension. |
| Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5). |
| An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location. |
| PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages. |
| PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own. |
| In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. |