CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2021-30298

    Last Modified: 21 Nov 2024

    Possible out of bound access due to improper validation of item size and DIAG memory pools data while switching between USB and PCIE interface in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.5
    High

    CVE-2021-30293

    Last Modified: 21 Nov 2024

    Possible assertion due to lack of input validation in PUSCH configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT

    Published: 3 Jan 2022
    7.8
    High

    CVE-2021-30289

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 3 Jan 2022
    7.1
    High

    CVE-2021-30283

    Last Modified: 21 Nov 2024

    Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 3 Jan 2022
    8.4
    High

    CVE-2021-30282

    Last Modified: 21 Nov 2024

    Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.8
    High

    CVE-2021-30279

    Last Modified: 21 Nov 2024

    Possible access control violation while setting current permission for VMIDs due to improper permission masking in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.1
    High

    CVE-2021-30278

    Last Modified: 21 Nov 2024

    Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    9.3
    Critical

    CVE-2021-30276

    Last Modified: 21 Nov 2024

    Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    9.3
    Critical

    CVE-2021-30275

    Last Modified: 21 Nov 2024

    Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    8.4
    High

    CVE-2021-30274

    Last Modified: 21 Nov 2024

    Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.5
    High

    CVE-2021-30273

    Last Modified: 21 Nov 2024

    Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

    Published: 3 Jan 2022
    7.3
    High

    CVE-2021-30272

    Last Modified: 21 Nov 2024

    Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.3
    High

    CVE-2021-30271

    Last Modified: 21 Nov 2024

    Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.3
    High

    CVE-2021-30270

    Last Modified: 21 Nov 2024

    Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.3
    High

    CVE-2021-30269

    Last Modified: 21 Nov 2024

    Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.8
    High

    CVE-2021-30268

    Last Modified: 21 Nov 2024

    Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 3 Jan 2022
    7.8
    High

    CVE-2021-30267

    Last Modified: 21 Nov 2024

    Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 3 Jan 2022
    8.4
    High

    CVE-2021-30262

    Last Modified: 21 Nov 2024

    Improper validation of a socket state when socket events are being sent to clients can lead to invalid access of memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 3 Jan 2022
    6.5
    Medium

    CVE-2021-1918

    Last Modified: 22 May 2025

    Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 3 Jan 2022
    7.1
    High

    CVE-2021-1894

    Last Modified: 21 Nov 2024

    Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    7.3
    High

    CVE-2020-11263

    Last Modified: 21 Nov 2024

    An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 3 Jan 2022
    8.8
    High

    CVE-2021-25994

    Last Modified: 21 Nov 2024

    In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.

    Published: 3 Jan 2022
    9.8
    Critical

    CVE-2021-25981

    Last Modified: 21 Nov 2024

    In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)

    Published: 3 Jan 2022
    5.3
    Medium

    CVE-2022-0079

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

    Published: 3 Jan 2022
    5.5
    Medium

    CVE-2021-45829

    Last Modified: 21 Nov 2024

    HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service.

    Published: 3 Jan 2022
    5.5
    Medium

    CVE-2022-0480

    Last Modified: 21 Nov 2024

    A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.

    Published: 3 Jan 2022
    7.8
    High

    CVE-2022-24958

    Last Modified: 21 Nov 2024

    drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

    Published: 3 Jan 2022
    5.5
    Medium

    CVE-2021-46141

    Last Modified: 21 Nov 2024

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

    Published: 3 Jan 2022
    5.5
    Medium

    CVE-2021-46142

    Last Modified: 21 Nov 2024

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

    Published: 3 Jan 2022
    9.8
    Critical

    CVE-2022-0080

    Last Modified: 22 May 2025

    mruby is vulnerable to Heap-based Buffer Overflow

    Published: 2 Jan 2022
    6.5
    Medium

    CVE-2022-22815

    Last Modified: 21 Nov 2024

    path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.

    Published: 2 Jan 2022
    6.5
    Medium

    CVE-2022-22816

    Last Modified: 21 Nov 2024

    path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

    Published: 2 Jan 2022
    4.2
    Medium

    CVE-2021-36751

    Last Modified: 21 Nov 2024

    ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.

    Published: 2 Jan 2022
    8.1
    High

    CVE-2021-41766

    Last Modified: 21 Nov 2024

    Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder).

    Published: 2 Jan 2022
    9.8
    Critical

    CVE-2022-22817

    Last Modified: 21 Nov 2024

    PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

    Published: 2 Jan 2022
    5.4
    Medium

    CVE-2022-22293

    Last Modified: 21 Nov 2024

    admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

    Published: 1 Jan 2022
    6.1
    Medium

    CVE-2021-44896

    Last Modified: 21 Nov 2024

    DMP Roadmap before 3.0.4 allows XSS.

    Published: 1 Jan 2022
    7.1
    High

    CVE-2021-45972

    Last Modified: 21 Nov 2024

    The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buffer with arbitrary data.

    Published: 1 Jan 2022
    8.8
    High

    CVE-2021-45960

    Last Modified: 5 May 2025

    In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

    Published: 1 Jan 2022
    7.8
    High

    CVE-2021-44852

    Last Modified: 21 Nov 2024

    An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device object and issue IOCTLs to read or write to arbitrary physical memory locations (or call an arbitrary address), leading to execution of arbitrary code. This is associated with 0x226040, 0x226044, and 0x226000.

    Published: 1 Jan 2022
    6.5
    Medium

    CVE-2021-43333

    Last Modified: 21 Nov 2024

    The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration settings.

    Published: 1 Jan 2022
    7.8
    High

    CVE-2021-45926

    Last Modified: 21 Nov 2024

    MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd0c689be0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _mdb_attempt_bind).

    Published: 31 Dec 2021
    7.8
    High

    CVE-2021-45927

    Last Modified: 21 Nov 2024

    MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd6e029ee0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _mdb_attempt_bind).

    Published: 31 Dec 2021
    5.5
    Medium

    CVE-2021-45928

    Last Modified: 21 Nov 2024

    libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState<jxl::FrameDecoder::ProcessSections).

    Published: 31 Dec 2021
    6.5
    Medium

    CVE-2021-45931

    Last Modified: 21 Nov 2024

    HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

    Published: 31 Dec 2021
    5.5
    Medium

    CVE-2021-45932

    Last Modified: 21 Nov 2024

    wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacket).

    Published: 31 Dec 2021
    5.5
    Medium

    CVE-2021-45933

    Last Modified: 21 Nov 2024

    wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacket).

    Published: 31 Dec 2021
    5.5
    Medium

    CVE-2021-45934

    Last Modified: 21 Nov 2024

    wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_HandlePacket and MqttClient_WaitType).

    Published: 31 Dec 2021
    5.5
    Medium

    CVE-2021-45935

    Last Modified: 21 Nov 2024

    Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

    Published: 31 Dec 2021
    5.5
    Medium

    CVE-2021-45936

    Last Modified: 21 Nov 2024

    wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttDecode_Disconnect (called from MqttClient_DecodePacket and MqttClient_WaitType).

    Published: 31 Dec 2021