Vulnerabilities (CVE)

Filtered by CWE-20
Total 9398 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0720 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2024-05-29 7.7 HIGH 8.0 HIGH
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary code. An attacker who successfully exploited the vulnerability could execute arbitrary code on the host operating system. The security update addresses the vulnerability by correcting how Windows Hyper-V Network Switch validates guest operating system network traffic.
CVE-2019-0718 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2024-05-29 5.5 MEDIUM 5.8 MEDIUM
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash. The update addresses the vulnerability by modifying how virtual machines access the Hyper-V Network Switch.
CVE-2019-0714 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2024-05-29 5.5 MEDIUM 5.8 MEDIUM
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash. The update addresses the vulnerability by modifying how virtual machines access the Hyper-V Network Switch.
CVE-2023-29332 1 Microsoft 1 Azure Kubernetes Service 2024-05-29 N/A 9.8 CRITICAL
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2020-1025 1 Microsoft 5 Lync, Sharepoint Enterprise Server, Sharepoint Foundation and 2 more 2024-05-28 7.5 HIGH 9.8 CRITICAL
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
CVE-2024-1481 2024-05-22 N/A N/A
A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.
CVE-2008-6662 2 Avg, Linux 2 Avg Anti-virus, Linux Kernel 2024-05-17 4.3 MEDIUM N/A
AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption.
CVE-2024-2248 2024-05-15 N/A N/A
A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.
CVE-2024-4142 2024-05-02 N/A N/A
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
CVE-2016-3739 1 Haxx 1 Curl 2024-05-01 2.6 LOW 5.3 MEDIUM
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.
CVE-2019-10190 2 Fedoraproject, Nic 2 Fedora, Knot Resolver 2024-04-26 5.0 MEDIUM 7.5 HIGH
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get passed through to the client even if its DNSSEC validation failed, instead of sending a SERVFAIL packet. Caching is not affected by this particular bug but see CVE-2019-10191.
CVE-2019-10191 2 Fedoraproject, Nic 2 Fedora, Knot Resolver 2024-04-26 5.0 MEDIUM 7.5 HIGH
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.
CVE-2024-4175 2024-04-25 N/A N/A
Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to send a malicious payload with Unicode characters that will be replaced by ASCII characters.
CVE-2023-21656 1 Qualcomm 256 Ar8035, Ar8035 Firmware, Csra6620 and 253 more 2024-04-12 N/A 7.8 HIGH
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
CVE-2023-21647 1 Qualcomm 86 Qca6390, Qca6390 Firmware, Qca6391 and 83 more 2024-04-12 N/A 6.5 MEDIUM
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
CVE-2022-34146 1 Qualcomm 194 Csr8811, Csr8811 Firmware, Ipq5010 and 191 more 2024-04-12 N/A 7.5 HIGH
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
CVE-2023-21657 1 Qualcomm 252 Csra6620, Csra6620 Firmware, Csra6640 and 249 more 2024-04-12 N/A 7.8 HIGH
Memoru corruption in Audio when ADSP sends input during record use case.
CVE-2022-33216 1 Qualcomm 36 Qam8295p, Qam8295p Firmware, Qca6574a and 33 more 2024-04-12 N/A 5.5 MEDIUM
Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file.
CVE-2022-40502 1 Qualcomm 192 Csr8811, Csr8811 Firmware, Ipq5010 and 189 more 2024-04-12 N/A 7.5 HIGH
Transient DOS due to improper input validation in WLAN Host.
CVE-2023-33014 1 Qualcomm 74 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 71 more 2024-04-12 N/A 6.8 MEDIUM
Information disclosure in Core services while processing a Diag command.