Aggregator
CVE-2024-45544 | Qualcomm Snapdragon Auto C-V2X 9150 up to WSA8830 IOCTL Call use after free
10 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT and Snapdragon Wearables. It has been rated as critical. This issue affects some unknown processing of the component IOCTL Call Handler. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-45544. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45543 | Qualcomm Snapdragon Auto C-V2X 9150 up to WSA8832 MSM Channel out-of-bounds write
10 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Wearables. It has been declared as critical. This vulnerability affects unknown code of the component MSM Channel Handler. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-45543. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45540 | Qualcomm Snapdragon Auto C-V2X 9150 up to WSA8830 IOCTP Map use after free
10 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Wearables. It has been classified as critical. This affects an unknown part of the component IOCTP Map Handler. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-45540. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43066 | Qualcomm Snapdragon Auto up to XR1 Platform File Descriptor use after free
10 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Wearables and classified as critical. Affected by this issue is some unknown functionality of the component File Descriptor Handler. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-43066. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Mozilla упрощает слежку за вами ради вашей же безопасности
10 months ago
Теперь браузер сам расскажет, какие данные у вас заберут, чтобы вы не переживали по пустякам.
CVE-2024-43067 | Qualcomm Snapdragon Auto C-V2X 9150 up to WSA8832 EEPROM toctou
10 months ago
A vulnerability has been found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Wearables and classified as critical. Affected by this vulnerability is an unknown functionality of the component EEPROM Handler. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-43067. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43058 | Qualcomm Snapdragon Mobile IOCTL Call type conversion
10 months ago
A vulnerability, which was classified as critical, was found in Qualcomm Snapdragon Mobile FastConnect 6900/FastConnect 7800/WCD9380/WSA8830/WSA8835. Affected is an unknown function of the component IOCTL Call Handler. The manipulation leads to incorrect type conversion.
This vulnerability is traded as CVE-2024-43058. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43065 | Qualcomm Snapdragon Auto up to WSA8845H RKP routine
10 months ago
A vulnerability, which was classified as problematic, has been found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Technology, Snapdragon WBC and Snapdragon Wearables. This issue affects some unknown processing of the component RKP. The manipulation leads to exposed dangerous routine.
The identification of this vulnerability is CVE-2024-43065. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45549 | Qualcomm Snapdragon Auto up to WSA8845H MQ Channel Creation exposure of sensitive system information to an unauthorized control sphere
10 months ago
A vulnerability classified as problematic was found in Qualcomm Snapdragon Auto, Snapdragon CCW, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon MC, Snapdragon MDM, Snapdragon Mobile, Snapdragon Technology, Snapdragon WBC and Snapdragon Wearables. This vulnerability affects unknown code of the component MQ Channel Creation. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability was named CVE-2024-45549. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33058 | Qualcomm Snapdragon Auto up to WSA8845H HLOS insufficient granularity of access control
10 months ago
A vulnerability classified as critical has been found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon MDM, Snapdragon Mobile, Snapdragon Technology and Snapdragon WBC. This affects an unknown part of the component HLOS. The manipulation leads to insufficient granularity of access control.
This vulnerability is uniquely identified as CVE-2024-33058. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43046 | Qualcomm Snapdragon Auto up to WSA8845H TZ Secure OS information disclosure
10 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon CCW, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon MDM, Snapdragon Mobile, Snapdragon Technology, Snapdragon Voice & Music, Snapdragon WBC, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking. It has been rated as problematic. Affected by this issue is some unknown functionality of the component TZ Secure OS. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-43046. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3405 | FCJ Venture Builder appclientefiel 3.0.27 HTTP GET Request ObterPedido ORDER_ID resource injection
10 months ago
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Request Handler. The manipulation of the argument ORDER_ID leads to improper control of resource identifiers.
This vulnerability is known as CVE-2025-3405. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
【原创漏洞】Vite任意文件读取漏洞(CVE-2025-31486)
10 months ago
近日,绿盟科技CERT监测到Vite发布安全公告,修复了Vite任意文件读取漏洞(CVE-2025-31486)。目前漏洞细节与PoC已公开,请相关用户尽快采取措施进行防护。
【原创漏洞】Vite任意文件读取漏洞(CVE-2025-31486)
10 months ago
近日,绿盟科技CERT监测到Vite发布安全公告,修复了Vite任意文件读取漏洞(CVE-2025-31486)。目前漏洞细节与PoC已公开,请相关用户尽快采取措施进行防护。
Apache Parquet 漏洞可致远程代码执行,数据安全告急
10 months ago
安全客
Submit #544136: FCJ Venture Builder appclientefiel 3.0.27 Insecure Direct Object Reference (IDOR) Exposing Sensitive Data [Accepted]
10 months ago
Submit #544136 / VDB-303649
Samuel Jesus
CVE-2025-3403 | Vivotek NVR ND8422P/NVR ND9525P/NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101 HTML Form sensitive information in source
10 months ago
A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been classified as problematic. Affected is an unknown function of the component HTML Form Handler. The manipulation leads to inclusion of sensitive information in source code.
This vulnerability is traded as CVE-2025-3403. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Signal, Трамп и обновление iOS: утечка гостайны началась с автозамены
10 months ago
Автоподсказка iPhone превратила секретный чат в достояние общественности.
网络时代 “家庭软暴力” 的连锁反应——从心理创伤到青少年网络安全危机
10 months ago
刘泽霖