Search Results (20296 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-27235 1 Google 1 Android 2025-04-03 5.5 Medium
In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-22006 1 Google 1 Android 2025-04-03 5.3 Medium
OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
CVE-2024-22007 1 Google 1 Android 2025-04-03 6.2 Medium
In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-22010 1 Google 1 Android 2025-04-03 5.5 Medium
In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-25984 1 Google 1 Android 2025-04-03 6.2 Medium
In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-25988 1 Google 1 Android 2025-04-03 8.4 High
In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-25989 1 Google 1 Android 2025-04-03 5.9 Medium
In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-25991 1 Google 1 Android 2025-04-03 3.3 Low
In acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-29032 1 Tendacn 2 Ac9, Ac9 Firmware 2025-04-03 5.9 Medium
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2024-35398 1 Totolink 3 Cp900 L, Cp900l, Cp900l Firmware 2025-04-03 9.8 Critical
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.
CVE-2024-35399 1 Totolink 2 Cp900l, Cp900l Firmware 2025-04-03 8.8 High
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth
CVE-2024-35400 1 Totolink 2 Cp900l, Cp900l Firmware 2025-04-03 5.3 Medium
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules
CVE-2024-37640 1 Totolink 2 A3700r, A3700r Firmware 2025-04-03 8.8 High
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.
CVE-2024-37639 1 Totolink 2 A3700r, A3700r Firmware 2025-04-03 8.8 High
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.
CVE-2024-37637 1 Totolink 2 A3700r, A3700r Firmware 2025-04-03 9.8 Critical
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.
CVE-2024-37634 1 Totolink 2 A3700r, A3700r Firmware 2025-04-03 9.8 Critical
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.
CVE-2024-37633 1 Totolink 2 A3700r, A3700r Firmware 2025-04-03 8.8 High
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg
CVE-2024-37631 1 Totolink 2 A3700r, A3700r Firmware 2025-04-03 8.8 High
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
CVE-2025-25610 1 Totolink 2 A3002r, A3002r Firmware 2025-04-03 8 High
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
CVE-2025-25609 1 Totolink 2 A3002r, A3002r Firmware 2025-04-03 8 High
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa