Export limit exceeded: 47122 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (47122 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-21649 | 1 Qualcomm | 130 Apq8096au, Apq8096au Firmware, Aqt1000 and 127 more | 2024-11-21 | 6.7 Medium |
| Memory corruption in WLAN while running doDriverCmd for an unspecific command. | ||||
| CVE-2023-21648 | 1 Qualcomm | 68 Aqt1000, Aqt1000 Firmware, Qca6391 and 65 more | 2024-11-21 | 6.7 Medium |
| Memory corruption in RIL while trying to send apdu packet. | ||||
| CVE-2023-21647 | 1 Qualcomm | 86 Qca6390, Qca6390 Firmware, Qca6391 and 83 more | 2024-11-21 | 6.5 Medium |
| Information disclosure in Bluetooth when an GATT packet is received due to improper input validation. | ||||
| CVE-2023-21643 | 1 Qualcomm | 48 Apq8064au, Apq8064au Firmware, Apq8096au and 45 more | 2024-11-21 | 9.1 Critical |
| Memory corruption due to untrusted pointer dereference in automotive during system call. | ||||
| CVE-2023-21627 | 1 Qualcomm | 96 Aqt1000, Aqt1000 Firmware, Qca6390 and 93 more | 2024-11-21 | 6.7 Medium |
| Memory corruption in Trusted Execution Environment while calling service API with invalid address. | ||||
| CVE-2023-21626 | 1 Qualcomm | 371 Apq8009, Apq8009 Firmware, Apq8017 and 368 more | 2024-11-21 | 7.1 High |
| Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | ||||
| CVE-2023-21625 | 1 Qualcomm | 92 Apq8009, Apq8009 Firmware, Apq8017 and 89 more | 2024-11-21 | 8.2 High |
| Information disclosure in Network Services due to buffer over-read while the device receives DNS response. | ||||
| CVE-2023-21412 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | 7.2 High |
| User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. | ||||
| CVE-2023-21411 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | 7.2 High |
| User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. | ||||
| CVE-2023-21410 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | 7.2 High |
| User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. | ||||
| CVE-2023-21409 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | 8.4 High |
| Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application. | ||||
| CVE-2023-21408 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | 8.4 High |
| Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems. | ||||
| CVE-2023-21407 | 1 Axis | 1 License Plate Verifier | 2024-11-21 | 8.8 High |
| A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. | ||||
| CVE-2023-21292 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-21290 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-21289 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-21288 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-21287 | 1 Google | 2 Admob, Android | 2024-11-21 | 9.8 Critical |
| In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-21286 | 1 Google | 1 Android | 2024-11-21 | 7.8 High |
| In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-21285 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||