Total
349 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-47295 | 1 Fortinet | 1 Fortios | 2025-06-04 | 3.4 Low |
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control. | ||||
CVE-2024-53019 | 2025-06-04 | 8.2 High | ||
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources. | ||||
CVE-2025-21463 | 2025-06-04 | 7.5 High | ||
Transient DOS while processing the EHT operation IE in the received beacon frame. | ||||
CVE-2024-53020 | 2025-06-04 | 8.2 High | ||
Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | ||||
CVE-2024-53021 | 2025-06-04 | 8.2 High | ||
Information disclosure may occur while processing goodbye RTCP packet from network. | ||||
CVE-2025-27029 | 2025-06-04 | 7.5 High | ||
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. | ||||
CVE-2024-53026 | 2025-06-04 | 8.2 High | ||
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | ||||
CVE-2023-33040 | 1 Qualcomm | 288 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 285 more | 2025-06-03 | 7.5 High |
Transient DOS in Data Modem during DTLS handshake. | ||||
CVE-2023-45919 | 1 Mesa3d | 1 Mesa | 2025-05-29 | 5.3 Medium |
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server. | ||||
CVE-2025-32053 | 1 Redhat | 2 Enterprise Linux, Rhel Eus | 2025-05-29 | 6.5 Medium |
A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read. | ||||
CVE-2025-32052 | 1 Redhat | 2 Enterprise Linux, Rhel Eus | 2025-05-29 | 6.5 Medium |
A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. | ||||
CVE-2022-2881 | 1 Isc | 1 Bind | 2025-05-28 | 5.5 Medium |
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process. | ||||
CVE-2023-51773 | 1 Bacnetstack | 1 Bacnet Stack | 2025-05-23 | 9.1 Critical |
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c. | ||||
CVE-2024-38135 | 1 Microsoft | 4 Windows 11 22h2, Windows 11 23h2, Windows 11 24h2 and 1 more | 2025-05-21 | 7.8 High |
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | ||||
CVE-2024-38127 | 1 Microsoft | 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more | 2025-05-21 | 7.8 High |
Windows Hyper-V Elevation of Privilege Vulnerability | ||||
CVE-2022-32166 | 2 Cloudbase, Debian | 2 Open Vswitch, Debian Linux | 2025-05-21 | 6.1 Medium |
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | ||||
CVE-2024-52879 | 2025-05-19 | 7.5 High | ||
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read. | ||||
CVE-2024-52878 | 2025-05-19 | 7.5 High | ||
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read. | ||||
CVE-2024-52877 | 2025-05-19 | 7.5 High | ||
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read. | ||||
CVE-2023-43533 | 1 Qualcomm | 476 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 473 more | 2025-05-15 | 7.5 High |
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |