Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-37029 Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized… Magma after 1.8.0 Fix from $1,9502025-01-21 HIGH 7.5 CVE-2023-37032 A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fe… Magma after 1.8.0 Fix from $1,9502025-01-21 MEDIUM 6.5 CVE-2023-37028 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma 1.9+ Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37030 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma after 1.8.0 Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37031 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma after 1.8.0 Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37033 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma after 1.8.0 Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37034 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma after 1.8.0 Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37036 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma after 1.8.0 Fix from $1,6002025-01-21 HIGH 7.5 CVE-2023-37024 A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486… Magma 1.9+ Fix from $1,9502025-01-21 MEDIUM 6.5 CVE-2023-37025 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma 1.9+ Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37026 A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90… Magma 1.9+ Fix from $1,6002025-01-21 MEDIUM 6.5 CVE-2023-37027 Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fe… Magma 1.9+ Fix from $1,6002025-01-21 CRITICAL 9.8 CVE-2024-20148 In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code executio… Yocto after 2.4 Fix from $2,3002025-01-06 HIGH 7.5 CVE-2024-20153 In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with n… Yocto after 3.5 Fix from $1,9502025-01-06 HIGH 8.1 CVE-2024-20146 In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code exec… Yocto after 2.5 Fix from $1,9502025-01-06 MEDIUM 6.7 CVE-2024-20140 In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious acto… Yocto Mitigation only Fix from $1,6002025-01-06 MEDIUM 6.6 CVE-2024-20143 In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has… Yocto Mitigation only Fix from $1,6002025-01-06 MEDIUM 6.6 CVE-2024-20144 In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has… Yocto Mitigation only Fix from $1,6002025-01-06 MEDIUM 6.6 CVE-2024-20145 In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has… Yocto Mitigation only Fix from $1,6002025-01-06 MEDIUM 6.5 CVE-2024-20139 In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of se… Yocto after 3.3 Fix from $1,6002024-12-02 HIGH 7.7 CVE-2022-31670 Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an i… Harbor 1.10.13 / 2.4.3+ Fix from $1,9502024-11-14 HIGH 7.4 CVE-2022-31671 Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request t… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 HIGH 7.7 CVE-2022-31668 Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 HIGH 7.7 CVE-2022-31669 Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy wit… Harbor 2.4.3 / 2.5.2+ Fix from $1,9502024-11-14 MEDIUM 6.4 CVE-2022-31667 Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access… Harbor 2.4.3 / 2.5.2+ Fix from $1,6002024-11-14 MEDIUM 5.4 CVE-2022-31666 Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of ot… Harbor 2.4.3 / 2.5.2+ Fix from $1,6002024-11-14 MEDIUM 6.2 CVE-2024-20107 In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execu… Yocto Mitigation only Fix from $1,6002024-11-04 HIGH 8.4 CVE-2024-20104 In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional exe… Yocto Mitigation only Fix from $1,9502024-11-04 CRITICAL 9.8 CVE-2024-48063 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch… Pytorch after 2.4.1 Fix from $2,3002024-10-29 MEDIUM 5.3 CVE-2024-9798 The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers. Zowe Api Mediation Layer 1.28.8 / 2.18.0+ Fix from $1,6002024-10-10