Search Results (19890 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-22233 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2024-11-21 5.5 Medium
After Affects versions 23.1 (and earlier), 22.6.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-21669 1 Qualcomm 122 Aqt1000, Aqt1000 Firmware, Flight Rb5 5g Platform and 119 more 2024-11-21 8.2 High
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
CVE-2023-21667 1 Qualcomm 86 Qca6390, Qca6390 Firmware, Qca6391 and 83 more 2024-11-21 6.5 Medium
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
CVE-2023-21661 1 Qualcomm 230 Ar8035, Ar8035 Firmware, Ar9380 and 227 more 2024-11-21 7.5 High
Transient DOS while parsing WLAN beacon or probe-response frame.
CVE-2023-21660 1 Qualcomm 158 Csr8811, Csr8811 Firmware, Immersive Home 214 Platform and 155 more 2024-11-21 7.5 High
Transient DOS in WLAN Firmware while parsing FT Information Elements.
CVE-2023-21659 1 Qualcomm 540 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 537 more 2024-11-21 7.5 High
Transient DOS in WLAN Firmware while processing frames with missing header fields.
CVE-2023-21658 1 Qualcomm 302 Ar8035, Ar8035 Firmware, Ar9380 and 299 more 2024-11-21 7.5 High
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
CVE-2023-21650 1 Qualcomm 102 Aqt1000, Aqt1000 Firmware, Csrb31024 and 99 more 2024-11-21 6.7 Medium
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
CVE-2023-21649 1 Qualcomm 130 Apq8096au, Apq8096au Firmware, Aqt1000 and 127 more 2024-11-21 6.7 Medium
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
CVE-2023-21639 1 Qualcomm 44 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 41 more 2024-11-21 6.7 Medium
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
CVE-2023-21636 1 Qualcomm 102 Aqt1000, Aqt1000 Firmware, Qca6390 and 99 more 2024-11-21 6.7 Medium
Memory Corruption due to improper validation of array index in Linux while updating adn record.
CVE-2023-21635 1 Qualcomm 98 Aqt1000, Aqt1000 Firmware, Csrb31024 and 95 more 2024-11-21 6.7 Medium
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
CVE-2023-21632 1 Qualcomm 50 Apq8064au, Apq8064au Firmware, Msm8996au and 47 more 2024-11-21 8.4 High
Memory corruption in Automotive GPU while querying a gsl memory node.
CVE-2023-21625 1 Qualcomm 92 Apq8009, Apq8009 Firmware, Apq8017 and 89 more 2024-11-21 8.2 High
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
CVE-2023-21620 2 Adobe, Microsoft 2 Framemaker, Windows 2024-11-21 5.5 Medium
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-21578 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2024-11-21 5.5 Medium
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-21577 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2024-11-21 5.5 Medium
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-21414 1 Axis 35 A8207-ve Mk Ii, Axis Os, M3215 and 32 more 2024-11-21 7.1 High
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
CVE-2023-21406 1 Axis 2 A1001, A1001 Firmware 2024-11-21 7.1 High
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible to write data beyond the heap allocated buffer. The data written outside the buffer could be used to execute arbitrary code.  lease refer to the Axis security advisory for more information, mitigation and affected products and software versions.
CVE-2023-21405 1 Axis 11 A1001, A1001 Firmware, A1210 \(-b\) and 8 more 2024-11-21 6.5 Medium
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.