Vulnerabilities (CVE)

Filtered by CWE-823
Total 63 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-0467 1 Imaginationtech 1 Ddk 2026-06-17 N/A 8.2 HIGH
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
CVE-2024-6603 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 7.4 HIGH
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-53017 1 Qualcomm 8 Sdm429w, Sdm429w Firmware, Snapdragon 429 Mobile Platform and 5 more 2026-06-17 N/A 6.6 MEDIUM
Memory corruption while handling test pattern generator IOCTL command.
CVE-2024-52939 2026-06-17 N/A 7.8 HIGH
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.
CVE-2024-52938 2026-06-17 N/A 7.8 HIGH
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.
CVE-2024-52937 2026-06-17 N/A 6.7 MEDIUM
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
CVE-2024-52936 2026-06-17 N/A 4.4 MEDIUM
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.
CVE-2024-52935 2026-06-17 N/A 4.1 MEDIUM
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
CVE-2024-49840 1 Qualcomm 20 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 17 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
CVE-2024-47900 2026-06-17 N/A 7.8 HIGH
Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
CVE-2024-47896 2026-06-17 N/A 3.3 LOW
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
CVE-2024-47895 2026-06-17 N/A 7.1 HIGH
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.
CVE-2024-47894 2026-06-17 N/A 7.1 HIGH
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.
CVE-2024-47893 2026-06-17 N/A 6.5 MEDIUM
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.
CVE-2024-45573 1 Qualcomm 48 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 45 more 2026-06-17 N/A 7.8 HIGH
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
CVE-2024-45570 1 Qualcomm 116 C-v2x 9150, C-v2x 9150 Firmware, Fastconnect 6800 and 113 more 2026-06-17 N/A 6.6 MEDIUM
Memory corruption may occur during IO configuration processing when the IO port count is invalid.
CVE-2024-45557 1 Qualcomm 122 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 119 more 2026-06-17 N/A 7.8 HIGH
Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
CVE-2024-43060 1 Qualcomm 82 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 79 more 2026-06-17 N/A 7.8 HIGH
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
CVE-2024-42416 1 Freebsd 1 Freebsd 2026-06-17 N/A 8.8 HIGH
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.
CVE-2024-42391 1 Cesanta 1 Mongoose 2026-06-17 N/A 4.3 MEDIUM
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.