Vulnerabilities (CVE)

Filtered by CWE-126
Total 177 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33048 1 Qualcomm 378 Ar8035, Ar8035 Firmware, Csr8811 and 375 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2024-33051 1 Qualcomm 578 315 5g Iot, 315 5g Iot Firmware, 9206 Lte and 575 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33047 1 Qualcomm 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more 2024-09-04 N/A 7.8 HIGH
Memory corruption when the captureRead QDCM command is invoked from user-space.
CVE-2024-33050 1 Qualcomm 514 Ar8035, Ar8035 Firmware, Ar9380 and 511 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33057 1 Qualcomm 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-23364 2024-09-03 N/A 7.5 HIGH
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-33043 2024-09-03 N/A 5.5 MEDIUM
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-23358 2024-09-03 N/A 7.5 HIGH
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-23359 2024-09-03 N/A 8.2 HIGH
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-21456 1 Qualcomm 84 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 81 more 2024-08-21 N/A 9.1 CRITICAL
Information Disclosure while parsing beacon frame in STA.
CVE-2024-7347 1 F5 2 Nginx Open Source, Nginx Plus 2024-08-20 N/A 4.7 MEDIUM
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2024-38127 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2024-08-16 N/A 7.8 HIGH
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2024-38135 1 Microsoft 4 Windows 11 22h2, Windows 11 23h2, Windows 11 24h2 and 1 more 2024-08-16 N/A 7.8 HIGH
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2024-21467 2024-08-06 N/A 6.5 MEDIUM
Information disclosure while handling beacon probe frame during scan entry generation in client side.
CVE-2024-21479 2024-08-06 N/A 7.5 HIGH
Transient DOS during music playback of ALAC content.
CVE-2024-21459 2024-08-06 N/A 6.5 MEDIUM
Information disclosure while handling beacon or probe response frame in STA.
CVE-2024-33020 2024-08-06 N/A 7.5 HIGH
Transient DOS while processing TID-to-link mapping IE elements.
CVE-2024-33015 2024-08-06 N/A 7.5 HIGH
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
CVE-2024-33019 2024-08-06 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping action frame.
CVE-2024-33018 2024-08-06 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.