Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1315/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-38442(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.5 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Oct 14, 2022 |
| CVE-2022-38441(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Oct 14, 2022 |
| CVE-2022-38440(opens NVD record) | High | 7.8 | Adobe Dimension versions 3.4.5 is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Oct 14, 2022 |
| CVE-2022-38437(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Oct 14, 2022 |
| CVE-2022-35691(opens NVD record) | Medium | 5.5 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Oct 14, 2022 |
| CVE-2022-2963(opens NVD record) | High | 7.5 | A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault. | Oct 14, 2022 |
| CVE-2022-2850(opens NVD record) | Medium | 6.5 | A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514. | Oct 14, 2022 |
| CVE-2022-41603(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41602(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41601(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41600(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41598(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41597(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41595(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41594(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41593(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41592(opens NVD record) | Low | 3.4 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | Oct 14, 2022 |
| CVE-2022-41589(opens NVD record) | High | 7.5 | The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability. | Oct 14, 2022 |
| CVE-2022-41588(opens NVD record) | High | 7.5 | The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity. | Oct 14, 2022 |
| CVE-2022-41587(opens NVD record) | Medium | 5.3 | Uncaptured exceptions in the home screen module. Successful exploitation of this vulnerability may affect stability. | Oct 14, 2022 |
| CVE-2022-41586(opens NVD record) | High | 7.5 | The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality. | Oct 14, 2022 |
| CVE-2022-41585(opens NVD record) | High | 7.8 | The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting. | Oct 14, 2022 |
| CVE-2022-41584(opens NVD record) | High | 7.8 | The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting. | Oct 14, 2022 |
| CVE-2022-41583(opens NVD record) | High | 7.5 | The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module. | Oct 14, 2022 |
| CVE-2022-41582(opens NVD record) | High | 7.5 | The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability. | Oct 14, 2022 |
| CVE-2022-41581(opens NVD record) | Critical | 9.1 | The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | Oct 14, 2022 |
| CVE-2022-41580(opens NVD record) | Critical | 9.8 | The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | Oct 14, 2022 |
| CVE-2022-41578(opens NVD record) | Critical | 9.8 | The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information. | Oct 14, 2022 |
| CVE-2022-41577(opens NVD record) | High | 7.1 | The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability. | Oct 14, 2022 |
| CVE-2022-41576(opens NVD record) | High | 7.8 | The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices. | Oct 14, 2022 |
| CVE-2022-39011(opens NVD record) | High | 7.5 | The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module. | Oct 14, 2022 |
| CVE-2022-38998(opens NVD record) | High | 7.5 | The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality. | Oct 14, 2022 |
| CVE-2022-38986(opens NVD record) | Critical | 9.1 | The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability. | Oct 14, 2022 |
| CVE-2022-38985(opens NVD record) | High | 7.5 | The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality. | Oct 14, 2022 |
| CVE-2022-38984(opens NVD record) | High | 7.5 | The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality. | Oct 14, 2022 |
| CVE-2022-38983(opens NVD record) | Critical | 9.8 | The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution. | Oct 14, 2022 |
| CVE-2022-38982(opens NVD record) | Critical | 9.8 | The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. | Oct 14, 2022 |
| CVE-2022-38981(opens NVD record) | High | 7.5 | The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage. | Oct 14, 2022 |
| CVE-2022-38980(opens NVD record) | Critical | 9.8 | The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions. | Oct 14, 2022 |
| CVE-2022-38977(opens NVD record) | High | 7.5 | The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data. | Oct 14, 2022 |
| CVE-2021-46840(opens NVD record) | Critical | 9.1 | The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | Oct 14, 2022 |
| CVE-2021-46839(opens NVD record) | Critical | 9.1 | The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | Oct 14, 2022 |
| CVE-2022-31123(opens NVD record) | Medium | 6.1 | Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources. | Oct 13, 2022 |
| CVE-2022-42889(opens NVD record) | Critical | 9.8 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default. | Oct 13, 2022 |
| CVE-2022-38902(opens NVD record) | Medium | 5.4 | A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic. | Oct 13, 2022 |
| CVE-2021-20030(opens NVD record) | High | 7.5 | SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files. | Oct 13, 2022 |
| CVE-2022-42897(opens NVD record) | Critical | 9.8 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected. | Oct 13, 2022 |
| CVE-2022-34391(opens NVD record) | High | 7.5 | Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | Oct 12, 2022 |
| CVE-2022-34390(opens NVD record) | High | 7.5 | Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | Oct 12, 2022 |
| CVE-2022-33937(opens NVD record) | High | 7.1 | Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potentially exploit this vulnerability, to gain unauthorized delete access to the files stored on the server filesystem, with the privileges of the GeoDrive service: NT AUTHORITY\SYSTEM. | Oct 12, 2022 |