CVE-2024-2167
Last Modified: 21 Mar 2024** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-2041. Reason: This candidate is a reservation duplicate of CVE-2024-2041. Notes: All CVE users should reference CVE-2024-2041 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2023-38362
Last Modified: 7 Jan 2025IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.
CVE-2023-5451
Last Modified: 15 Apr 2026Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
CVE-2022-43890
Last Modified: 8 May 2025IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453.
CVE-2024-24901
Last Modified: 20 Feb 2026Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.
CVE-2024-22463
Last Modified: 20 Feb 2026Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information
CVE-2024-22452
Last Modified: 31 Jan 2025Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability by modifying files in the installation folder to execute arbitrary code, leading to privilege escalation.
CVE-2023-6241
Last Modified: 13 Mar 2025Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r11p0 through r25p0; Valhall GPU Kernel Driver: from r19p0 through r25p0, from r29p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.
CVE-2023-43553
Last Modified: 9 Jan 2025Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
CVE-2023-43552
Last Modified: 11 Aug 2025Memory corruption while processing MBSSID beacon containing several subelement IE.
CVE-2023-43550
Last Modified: 11 Aug 2025Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
CVE-2023-43549
Last Modified: 10 Jan 2025Memory corruption while processing TPC target power table in FTM TPC.
CVE-2023-43548
Last Modified: 11 Aug 2025Memory corruption while parsing qcp clip with invalid chunk data size.
CVE-2023-43547
Last Modified: 11 Aug 2025Memory corruption while invoking IOCTLs calls in Automotive Multimedia.
CVE-2023-43546
Last Modified: 11 Aug 2025Memory corruption while invoking HGSL IOCTL context create.
CVE-2023-43541
Last Modified: 10 Jan 2025Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.
CVE-2023-43540
Last Modified: 10 Jan 2025Memory corruption while processing the IOCTL FM HCI WRITE request.
CVE-2023-43539
Last Modified: 10 Jan 2025Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
CVE-2023-33105
Last Modified: 10 Jan 2025Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
CVE-2023-33104
Last Modified: 11 Aug 2025Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
CVE-2023-33103
Last Modified: 10 Jan 2025Transient DOS while processing CAG info IE received from NW.
CVE-2023-33096
Last Modified: 11 Aug 2025Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
CVE-2023-33095
Last Modified: 11 Aug 2025Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
CVE-2023-33090
Last Modified: 10 Jan 2025Transient DOS while processing channel information for speaker protection v2 module in ADSP.
CVE-2023-33086
Last Modified: 11 Aug 2025Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
CVE-2023-33084
Last Modified: 10 Jan 2025Transient DOS while processing IE fragments from server during DTLS handshake.
CVE-2023-33078
Last Modified: 10 Jan 2025Information Disclosure while processing IOCTL request in FastRPC.
CVE-2023-33066
Last Modified: 11 Aug 2025Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-28582
Last Modified: 10 Jan 2025Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
CVE-2023-28578
Last Modified: 11 Aug 2025Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2023-6143
Last Modified: 27 Mar 2025Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r1p0 through r18p0; Valhall GPU Kernel Driver: from r37p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.
CVE-2024-0155
Last Modified: 8 Jan 2025Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code.
CVE-2024-27351
Last Modified: 4 Nov 2025In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.
CVE-2024-0156
Last Modified: 8 Jan 2025Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.
CVE-2023-4479
Last Modified: 23 Feb 2026Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
CVE-2024-21826
Last Modified: 16 Dec 2024in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.
CVE-2024-21816
Last Modified: 16 Dec 2024in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.
CVE-2023-49602
Last Modified: 16 Dec 2024in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2023-46708
Last Modified: 16 Dec 2024in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.
CVE-2023-25176
Last Modified: 16 Dec 2024in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-20038
Last Modified: 22 Apr 2025In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495932; Issue ID: ALPS08495932.
CVE-2024-20037
Last Modified: 22 Apr 2025In pq, there is a possible write-what-where condition due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495937; Issue ID: ALPS08495937.
CVE-2024-20036
Last Modified: 22 Apr 2025In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.
CVE-2024-20034
Last Modified: 22 Apr 2025In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849.
CVE-2024-20033
Last Modified: 22 Apr 2025In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08499945; Issue ID: ALPS08499945.
CVE-2024-20032
Last Modified: 22 Apr 2025In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08487630; Issue ID: MSV-1020.
CVE-2024-20029
Last Modified: 22 Apr 2025In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477406; Issue ID: MSV-1010.
CVE-2024-20031
Last Modified: 22 Apr 2025In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541742.
CVE-2024-20030
Last Modified: 22 Apr 2025In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741.
CVE-2024-20028
Last Modified: 22 Apr 2025In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541687.
