CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-2167

    Last Modified: 21 Mar 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-2041. Reason: This candidate is a reservation duplicate of CVE-2024-2041. Notes: All CVE users should reference CVE-2024-2041 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 4 Mar 2024
    5.3
    Medium

    CVE-2023-38362

    Last Modified: 7 Jan 2025

    IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.

    Published: 4 Mar 2024
    6.1
    Medium

    CVE-2023-5451

    Last Modified: 15 Apr 2026

    Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.

    Published: 4 Mar 2024
    5.3
    Medium

    CVE-2022-43890

    Last Modified: 8 May 2025

    IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453.

    Published: 4 Mar 2024
    3
    Low

    CVE-2024-24901

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.

    Published: 4 Mar 2024
    7.4
    High

    CVE-2024-22463

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information

    Published: 4 Mar 2024
    7.3
    High

    CVE-2024-22452

    Last Modified: 31 Jan 2025

    Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability by modifying files in the installation folder to execute arbitrary code, leading to privilege escalation.

    Published: 4 Mar 2024
    7
    High

    CVE-2023-6241

    Last Modified: 13 Mar 2025

    Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r11p0 through r25p0; Valhall GPU Kernel Driver: from r19p0 through r25p0, from r29p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.

    Published: 4 Mar 2024
    9.8
    Critical

    CVE-2023-43553

    Last Modified: 9 Jan 2025

    Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.

    Published: 4 Mar 2024
    9.8
    Critical

    CVE-2023-43552

    Last Modified: 11 Aug 2025

    Memory corruption while processing MBSSID beacon containing several subelement IE.

    Published: 4 Mar 2024
    7.8
    High

    CVE-2023-43550

    Last Modified: 11 Aug 2025

    Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-43549

    Last Modified: 10 Jan 2025

    Memory corruption while processing TPC target power table in FTM TPC.

    Published: 4 Mar 2024
    7.3
    High

    CVE-2023-43548

    Last Modified: 11 Aug 2025

    Memory corruption while parsing qcp clip with invalid chunk data size.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-43547

    Last Modified: 11 Aug 2025

    Memory corruption while invoking IOCTLs calls in Automotive Multimedia.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-43546

    Last Modified: 11 Aug 2025

    Memory corruption while invoking HGSL IOCTL context create.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-43541

    Last Modified: 10 Jan 2025

    Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-43540

    Last Modified: 10 Jan 2025

    Memory corruption while processing the IOCTL FM HCI WRITE request.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-43539

    Last Modified: 10 Jan 2025

    Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33105

    Last Modified: 10 Jan 2025

    Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33104

    Last Modified: 11 Aug 2025

    Transient DOS while processing PDU Release command with a parameter PDU ID out of range.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33103

    Last Modified: 10 Jan 2025

    Transient DOS while processing CAG info IE received from NW.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33096

    Last Modified: 11 Aug 2025

    Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33095

    Last Modified: 11 Aug 2025

    Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.

    Published: 4 Mar 2024
    5.5
    Medium

    CVE-2023-33090

    Last Modified: 10 Jan 2025

    Transient DOS while processing channel information for speaker protection v2 module in ADSP.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33086

    Last Modified: 11 Aug 2025

    Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-33084

    Last Modified: 10 Jan 2025

    Transient DOS while processing IE fragments from server during DTLS handshake.

    Published: 4 Mar 2024
    5.1
    Medium

    CVE-2023-33078

    Last Modified: 10 Jan 2025

    Information Disclosure while processing IOCTL request in FastRPC.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-33066

    Last Modified: 11 Aug 2025

    Memory corruption in Audio while processing RT proxy port register driver.

    Published: 4 Mar 2024
    9.8
    Critical

    CVE-2023-28582

    Last Modified: 10 Jan 2025

    Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.

    Published: 4 Mar 2024
    9.3
    Critical

    CVE-2023-28578

    Last Modified: 11 Aug 2025

    Memory corruption in Core Services while executing the command for removing a single event listener.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2023-6143

    Last Modified: 27 Mar 2025

    Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r1p0 through r18p0; Valhall GPU Kernel Driver: from r37p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.

    Published: 4 Mar 2024
    7
    High

    CVE-2024-0155

    Last Modified: 8 Jan 2025

    Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code.

    Published: 4 Mar 2024
    5.3
    Medium

    CVE-2024-27351

    Last Modified: 4 Nov 2025

    In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

    Published: 4 Mar 2024
    7
    High

    CVE-2024-0156

    Last Modified: 8 Jan 2025

    Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.

    Published: 4 Mar 2024
    7.3
    High

    CVE-2023-4479

    Last Modified: 23 Feb 2026

    Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.

    Published: 4 Mar 2024
    4.3
    Medium

    CVE-2024-21826

    Last Modified: 16 Dec 2024

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

    Published: 4 Mar 2024
    4
    Medium

    CVE-2024-21816

    Last Modified: 16 Dec 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

    Published: 4 Mar 2024
    2.9
    Low

    CVE-2023-49602

    Last Modified: 16 Dec 2024

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

    Published: 4 Mar 2024
    4.3
    Medium

    CVE-2023-46708

    Last Modified: 16 Dec 2024

    in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

    Published: 4 Mar 2024
    2.9
    Low

    CVE-2023-25176

    Last Modified: 16 Dec 2024

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

    Published: 4 Mar 2024
    3.4
    Low

    CVE-2024-20038

    Last Modified: 22 Apr 2025

    In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495932; Issue ID: ALPS08495932.

    Published: 4 Mar 2024
    6.7
    Medium

    CVE-2024-20037

    Last Modified: 22 Apr 2025

    In pq, there is a possible write-what-where condition due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495937; Issue ID: ALPS08495937.

    Published: 4 Mar 2024
    4.4
    Medium

    CVE-2024-20036

    Last Modified: 22 Apr 2025

    In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.

    Published: 4 Mar 2024
    7.2
    High

    CVE-2024-20034

    Last Modified: 22 Apr 2025

    In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849.

    Published: 4 Mar 2024
    4.4
    Medium

    CVE-2024-20033

    Last Modified: 22 Apr 2025

    In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08499945; Issue ID: ALPS08499945.

    Published: 4 Mar 2024
    6.7
    Medium

    CVE-2024-20032

    Last Modified: 22 Apr 2025

    In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08487630; Issue ID: MSV-1020.

    Published: 4 Mar 2024
    8.4
    High

    CVE-2024-20029

    Last Modified: 22 Apr 2025

    In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477406; Issue ID: MSV-1010.

    Published: 4 Mar 2024
    6.7
    Medium

    CVE-2024-20031

    Last Modified: 22 Apr 2025

    In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541742.

    Published: 4 Mar 2024
    4.4
    Medium

    CVE-2024-20030

    Last Modified: 22 Apr 2025

    In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741.

    Published: 4 Mar 2024
    6.6
    Medium

    CVE-2024-20028

    Last Modified: 22 Apr 2025

    In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541687.

    Published: 4 Mar 2024