Unknown · CVSS Not scored
SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.
Published Jun 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.
Published Jun 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as multiple concatenated email addresses. NOTE: the PostSRSd maintainer acknowledges "theoretically, this error should never occur ... I'm not sure if there's a reliable way to trigger this condition by an external attacker, but it is a security bug in PostSRSd nevertheless."
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.
Published Jun 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via multiple models that contain a 'note' field to store additional information.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML via the User Avatar attribute.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Gitpod before 0.6.0 allows unvalidated redirects.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Ticket Article detail view.
Published Jun 28, 2021 · Updated Aug 4, 2024
Medium · CVSS 6.7
An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Critical · CVSS 9.8
Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.5
Improper validation of tag id while RRC sending tag id to MAC can lead to TOCTOU race condition in Snapdragon Connectivity, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.8
Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. NOTE: the vendor's position is that the product is not intended for opening an untrusted project file
Published Jun 21, 2021 · Updated Aug 4, 2024
High · CVSS 8.8
Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT
Published Jun 14, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
Published Jun 23, 2021 · Updated Aug 4, 2024
High · CVSS 8.4
Improper buffer initialization on the backend driver can lead to buffer overflow in Snapdragon Auto
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.5
RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 8.4
Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.8
Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.7
Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.1
Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.7
Processing DCB/AVB algorithm with an invalid queue index from IOCTL request could lead to arbitrary address modification in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 8.4
A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 5.5
Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Published Jun 14, 2022 · Updated Aug 4, 2024
Critical · CVSS 9.3
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.8
Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.2
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.7
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.5
Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 8.4
Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 8.4
Memory corruption in graphics support layer due to use after free condition in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 5.5
Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 5.5
Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Critical · CVSS 9.1
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 8.2
Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.7
An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.5
Possible assertion due to improper validation of rank restriction field in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.7
Improper validation of session id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.5
Possible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
Medium · CVSS 5.5
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.5
Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 8.4
Possible out of bounds read due to improper typecasting while handling page fault for global memory in Snapdragon Connectivity, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.5
Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.
Published Jun 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
Published Jun 21, 2021 · Updated Aug 4, 2024
High · CVSS 7.8
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024
High · CVSS 7.5
Possible buffer over read due to improper validation of SIB type when processing a NR system Information message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Published Jun 14, 2022 · Updated Aug 4, 2024