Unknown · CVSS Not scored
In cmdq, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS07636133.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In cmdq, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS07636130.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In cmdq, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS07634601.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628604; Issue ID: ALPS07628582.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ALPS07573202.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In pqframework, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629585; Issue ID: ALPS07629584.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07559800.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In display, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671046; Issue ID: ALPS07671046.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441796; Issue ID: ALPS07441796.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07611449; Issue ID: ALPS07441735.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460390; Issue ID: ALPS07588667.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07509605.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07588343.
Published Jul 4, 2023 · Updated Dec 4, 2024
High · CVSS 7.1
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.
Published Jul 3, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In FM service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID: ALPS07664711.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664720; Issue ID: ALPS07664720.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664731; Issue ID: ALPS07664731.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ALPS07664735.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ALPS07664741.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07978760; Issue ID: ALPS07363410.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292228; Issue ID: ALPS07292228.
Published Jul 4, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a malicious shared library and use LD_PRELOAD to bypass authorization checks.
Published Jul 5, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
Published Jul 5, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
High · CVSS 7.2
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
Published Jul 5, 2023 · Updated Dec 4, 2024
High · CVSS 7.2
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published Jul 5, 2023 · Updated Dec 4, 2024
High · CVSS 7.2
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published Jul 5, 2023 · Updated Dec 4, 2024
Medium · CVSS 6.5
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
Published Jul 5, 2023 · Updated Dec 4, 2024
Medium · CVSS 6.5
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
Published Jul 5, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Medium · CVSS 6.5
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
Published Jul 5, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Medium · CVSS 5.3
There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller.
Published Jul 5, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
High · CVSS 8.6
An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.
Published Jul 11, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Published Jul 12, 2023 · Updated Dec 4, 2024
Unknown · CVSS Not scored
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Published Jul 12, 2023 · Updated Dec 4, 2024