Search Results (35128 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-39063 1 Open5gs 1 Open5gs 2024-11-21 7.5 High
When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once UPF receives a request, it gets the f_teid_len from incoming message, and then uses it to copy data from incoming message to struct f_teid without checking the maximum length. If the pdi.local_f_teid.len exceeds the maximum length of the struct of f_teid, the memcpy() overwrites the fields (e.g., f_teid_len) after f_teid in the pdr struct. After parsing the request, the UPF starts to build a response. The f_teid_len with its overwritten value is used as a length for memcpy(). A segmentation fault occurs, as a result of a memcpy(), if this overwritten value is large enough.
CVE-2022-39013 1 Sap 1 Business Objects Business Intelligence Platform 2024-11-21 7.6 High
Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker to modify system data and make the system unavailable leading to high impact on confidentiality and low impact on integrity and availability of the application.
CVE-2022-39000 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 9.8 Critical
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
CVE-2022-38997 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38996 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38995 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38994 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38993 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38992 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38991 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38990 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38989 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38988 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38987 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38979 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38978 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38973 1 Intel 4 Arc A750, Arc A750 Firmware, Arc A770 and 1 more 2024-11-21 3.3 Low
Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow an authenticated user to potentially enable denial of service or infomation disclosure via local access.
CVE-2022-38795 1 Gitea 1 Gitea 2024-11-21 6.5 Medium
In Gitea through 1.17.1, repo cloning can occur in the migration function.
CVE-2022-38772 1 Zohocorp 6 Manageengine Netflow Analyzer, Manageengine Network Configuration Manager, Manageengine Opmanager and 3 more 2024-11-21 8.8 High
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
CVE-2022-38621 1 Doufox 1 Doufox 2024-11-21 9.8 Critical
Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.