Vulnerabilities (CVE)

Filtered by CWE-126
Total 194 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33070 1 Qualcomm 10 Mdm9628, Mdm9628 Firmware, Qca6564a and 7 more 2024-10-16 N/A 7.5 HIGH
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33071 1 Qualcomm 10 Mdm9628, Mdm9628 Firmware, Qca6564a and 7 more 2024-10-16 N/A 7.5 HIGH
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
CVE-2024-33073 1 Qualcomm 318 Ar8035, Ar8035 Firmware, Csr8811 and 315 more 2024-10-16 N/A 8.2 HIGH
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-38397 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 229 more 2024-10-16 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame.
CVE-2024-9029 2024-09-30 N/A 7.5 HIGH
A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked to the library, resulting in a denial of service.
CVE-2024-38250 1 Microsoft 16 Office, Office Long Term Servicing Channel, Windows 10 1507 and 13 more 2024-09-17 N/A 7.8 HIGH
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-43475 1 Microsoft 1 Windows Server 2008 2024-09-13 N/A 7.3 HIGH
Microsoft Windows Admin Center Information Disclosure Vulnerability
CVE-2024-33048 1 Qualcomm 378 Ar8035, Ar8035 Firmware, Csr8811 and 375 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
CVE-2024-33051 1 Qualcomm 578 315 5g Iot, 315 5g Iot Firmware, 9206 Lte and 575 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33047 1 Qualcomm 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more 2024-09-04 N/A 7.8 HIGH
Memory corruption when the captureRead QDCM command is invoked from user-space.
CVE-2024-33050 1 Qualcomm 514 Ar8035, Ar8035 Firmware, Ar9380 and 511 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33057 1 Qualcomm 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more 2024-09-04 N/A 7.5 HIGH
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
CVE-2024-23364 2024-09-03 N/A 7.5 HIGH
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-33043 2024-09-03 N/A 5.5 MEDIUM
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-23358 2024-09-03 N/A 7.5 HIGH
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-23359 2024-09-03 N/A 8.2 HIGH
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-21456 1 Qualcomm 84 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 81 more 2024-08-21 N/A 9.1 CRITICAL
Information Disclosure while parsing beacon frame in STA.
CVE-2024-7347 1 F5 2 Nginx Open Source, Nginx Plus 2024-08-20 N/A 4.7 MEDIUM
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2024-38127 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2024-08-16 N/A 7.8 HIGH
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2024-38135 1 Microsoft 4 Windows 11 22h2, Windows 11 23h2, Windows 11 24h2 and 1 more 2024-08-16 N/A 7.8 HIGH
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability