CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49142
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

Jan 2, 2024
CVE-2023-49135
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Jan 2, 2024
CVE-2023-48360
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Jan 2, 2024
CVE-2023-47857
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

Jan 2, 2024
CVE-2023-47216
2.9 LOW

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources

Jan 2, 2024
CVE-2023-47039
7.8 HIGH

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell …

Jan 2, 2024
CVE-2023-43514
8.4 HIGH

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

Jan 2, 2024
CVE-2023-43512
7.5 HIGH

Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual …

Jan 2, 2024
CVE-2023-43511
7.5 HIGH

Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

Jan 2, 2024
CVE-2023-33120
7.8 HIGH

Memory corruption in Audio when memory map command is executed consecutively in ADSP.

Jan 2, 2024
CVE-2023-33118
7.8 HIGH

Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.

Jan 2, 2024
CVE-2023-33117
7.8 HIGH

Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

Jan 2, 2024
CVE-2023-33116
7.5 HIGH

Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

Jan 2, 2024
CVE-2023-33114
8.4 HIGH

Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

Jan 2, 2024
CVE-2023-33113
8.4 HIGH

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

Jan 2, 2024
CVE-2023-33112
7.5 HIGH

Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.

Jan 2, 2024
CVE-2023-33110
7.8 HIGH

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close …

Jan 2, 2024
CVE-2023-33109
7.5 HIGH

Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

Jan 2, 2024
CVE-2023-33108
8.4 HIGH

Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.

Jan 2, 2024
CVE-2023-33094
8.4 HIGH

Memory corruption while running VK synchronization with KASAN enabled.

Jan 2, 2024
CVE-2023-33085
7.8 HIGH

Memory corruption in wearables while processing data from AON.

Jan 2, 2024
CVE-2023-33062
7.5 HIGH

Transient DOS in WLAN Firmware while parsing a BTM request.

Jan 2, 2024
CVE-2023-33040
7.5 HIGH

Transient DOS in Data Modem during DTLS handshake.

Jan 2, 2024
CVE-2023-33038
6.7 MEDIUM

Memory corruption while receiving a message in Bus Socket Transport Server.

Jan 2, 2024
CVE-2023-33037
7.1 HIGH

Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.

Jan 2, 2024
CVE-2023-33036
7.1 HIGH

Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.

Jan 2, 2024
CVE-2023-33033
8.4 HIGH

Memory corruption in Audio during playback with speaker protection.

Jan 2, 2024
CVE-2023-33032
9.3 CRITICAL

Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

Jan 2, 2024
CVE-2023-33030
9.3 CRITICAL

Memory corruption in HLOS while running playready use-case.

Jan 2, 2024
CVE-2023-33025
9.8 CRITICAL

Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.

Jan 2, 2024
CVE-2023-33014
7.6 HIGH

Information disclosure in Core services while processing a Diag command.

Jan 2, 2024
CVE-2023-28583
6.7 MEDIUM

Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.

Jan 2, 2024
CVE-2023-26159
7.3 HIGH

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When …

Jan 2, 2024
CVE-2023-26157
5.5 MEDIUM

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

Jan 2, 2024
CVE-2023-32891
6.7 MEDIUM

In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32890
7.5 HIGH

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional …

Jan 2, 2024
CVE-2023-32889
7.5 HIGH

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial …

Jan 2, 2024
CVE-2023-32888
7.5 HIGH

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial …

Jan 2, 2024
CVE-2023-32887
7.5 HIGH

In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with …

Jan 2, 2024
CVE-2023-32886
7.5 HIGH

In Modem IMS SMS UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial …

Jan 2, 2024
CVE-2023-32885
6.7 MEDIUM

In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System …

Jan 2, 2024
CVE-2023-32884
6.7 MEDIUM

In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution …

Jan 2, 2024
CVE-2023-32883
6.7 MEDIUM

In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Jan 2, 2024
CVE-2023-32882
6.7 MEDIUM

In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution …

Jan 2, 2024
CVE-2023-32881
4.4 MEDIUM

In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. …

Jan 2, 2024
CVE-2023-32880
4.4 MEDIUM

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32879
6.7 MEDIUM

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32878
4.4 MEDIUM

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32877
6.7 MEDIUM

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32876
4.4 MEDIUM

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.