|
209991
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9650 mdm9635m mdm9655 mdm9625 mdm9640 mdm9645 sdm630 qca6174a qca6574au qca6584au qca9379 msm8976 msm8937 msm8952 apq8096au msm8996au msm8917 qca…
|
Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdr…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11140
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209992
|
7.5 |
HIGH
Network
|
qualcomm
|
msm8996au apq8017 apq8037 apq8052 apq8053 apq8056 apq8064au apq8076 apq8096au aqt1000 ar8031 ar8035 csra6620 csra6640 mdm9640 mdm9650 msm8917 msm892…
|
Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11139
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209993
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8960 mdm9607 mdm9650 msm8909w mdm9635m mdm9655 mdm9615 mdm9625 mdm9640 mdm9645 sdm630 qca6174a qca6574au qca6584au qca9379 msm8976 msm8952 apq809…
|
Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-11138
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209994
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8960 mdm9607 mdm9650 msm8909w mdm9635m mdm9655 mdm9615 mdm9625 mdm9640 mdm9645 sdm630 qca6174a qca6574au qca6584au qca9379 msm8976 msm8952 apq809…
|
Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Comp…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-11137
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209995
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8960 mdm9206 mdm9607 mdm9650 msm8909w mdm9635m mdm9655 mdm9615 mdm9625 mdm9640 mdm9645 qca9379 msm8976 sdm630 qca6584au qca6584 qca6574au qca6174…
|
Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory requirement in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11136
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209996
|
9.8 |
CRITICAL
Network
|
webswing
|
webswing
|
JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-11103
|
2024-11-21 13:56 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209997
|
7.5 |
HIGH
Network
|
linuxfoundation
|
indy-node
|
Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12.4, there is lack of signature verification on a s…
|
-
|
CVE-2020-11093
|
2024-11-21 13:56 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209998
|
5.3 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this param…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-10770
|
2024-11-21 13:56 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209999
|
7.5 |
HIGH
Network
|
nlnetlabs
|
unbound
|
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query int…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-10772
|
2024-11-21 13:56 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210000
|
5.5 |
MEDIUM
Local
|
heketi_project redhat
|
heketi enterprise_linux gluster_storage openshift_container_platform
|
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-10763
|
2024-11-21 13:56 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|