Vulnerabilities (CVE)

Filtered by CWE-125
Total 7206 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25942 1 Hdfgroup 1 Hdf5 2024-11-21 N/A 7.8 HIGH
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-25872 1 Fast String Search Project 1 Fast String Search 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.
CVE-2022-25821 2 Google, Samsung 2 Android, Exynos 2024-11-21 3.6 LOW 3.3 LOW
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
CVE-2022-25819 2 Google, Samsung 2 Android, Exynos 2024-11-21 2.1 LOW 5.3 MEDIUM
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.
CVE-2022-25794 1 Autodesk 1 Fbx Review 2024-11-21 6.8 MEDIUM 7.8 HIGH
An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScript Byte Code 'ABC' files or information disclosure. ABC files are created by the Flash compiler and contain executable code. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
CVE-2022-25747 1 Qualcomm 24 Mdm8207, Mdm8207 Firmware, Mdm9205 and 21 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message
CVE-2022-25738 1 Qualcomm 70 Ar8031, Ar8031 Firmware, Csra6620 and 67 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in modem due to buffer over-red while performing checksum of packet received
CVE-2022-25732 1 Qualcomm 66 Ar8031, Ar8031 Firmware, Csra6620 and 63 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in modem due to buffer over read in dns client due to missing length check
CVE-2022-25731 1 Qualcomm 26 Mdm8207, Mdm8207 Firmware, Mdm9205 and 23 more 2024-11-21 N/A 7.5 HIGH
Information disclosure in modem due to buffer over-read while processing packets from DNS server
CVE-2022-25730 1 Qualcomm 54 Mdm8207, Mdm8207 Firmware, Mdm9205 and 51 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in modem due to improper check of IP type while processing DNS server query
CVE-2022-25728 1 Qualcomm 68 Ar8031, Ar8031 Firmware, Csra6620 and 65 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in modem due to buffer over-read while processing response from DNS server
CVE-2022-25726 1 Qualcomm 52 Mdm8207, Mdm8207 Firmware, Mdm9205 and 49 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet
CVE-2022-25706 1 Qualcomm 257 Apq8009w, Apq8009w Firmware, Apq8017 and 254 more 2024-11-21 N/A 8.2 HIGH
Information disclosure in Bluetooth driver due to buffer over-read while reading l2cap length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
CVE-2022-25670 1 Qualcomm 251 Apq8009, Apq8009 Firmware, Apq8009w and 248 more 2024-11-21 N/A 7.5 HIGH
Denial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVE-2022-25669 1 Qualcomm 281 Apq8009, Apq8009 Firmware, Apq8009w and 278 more 2024-11-21 N/A 7.5 HIGH
Denial of service in video due to buffer over read while parsing MP4 clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVE-2022-25653 1 Qualcomm 179 Apq8053, Apq8053 Firmware, Aqt1000 and 176 more 2024-11-21 N/A 6.8 MEDIUM
Information disclosure in video due to buffer over-read while processing avi file in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
CVE-2022-24971 2 Foxit, Microsoft 3 Pdf Editor, Pdf Reader, Windows 2024-11-21 6.8 MEDIUM 8.8 HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15812.
CVE-2022-24908 2 Foxit, Microsoft 3 Pdf Editor, Pdf Reader, Windows 2024-11-21 N/A 7.8 HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16187.
CVE-2022-24907 2 Foxit, Microsoft 3 Pdf Editor, Pdf Reader, Windows 2024-11-21 N/A 7.8 HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16186.
CVE-2022-24786 2 Debian, Pjsip 2 Debian Linux, Pjsip 2024-11-21 7.5 HIGH 9.8 CRITICAL
PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.