A vulnerability was found in Mozilla Firefox up to 100 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component Download Handler. The manipulation leads to escaping of output.
This vulnerability was named CVE-2022-31739. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 5.14-rc2. Affected by this issue is some unknown functionality of the component Tracing Module. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2021-3679. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in NVIDIA GPU Display Driver on Linux. This affects an unknown part of the component Kernel Mode Layer. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2022-31615. Attacking locally is a requirement. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.6.17/6.7.5 on ACPI. It has been rated as problematic. Affected by this issue is the function its_probe_one of the component Quirks Handler. The manipulation leads to privilege escalation.
This vulnerability is handled as CVE-2024-26823. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Android and classified as problematic. Affected by this issue is the function create_pinctrl of the file core.c. The manipulation leads to use after free.
This vulnerability is handled as CVE-2020-0427. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.3.2. Affected is the function write_tpt_entry of the file drivers/infiniband/hw/cxgb4/mem.c of the component cxgb4 Driver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2019-17075. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Oracle MySQL Server up to 8.0.21. It has been rated as critical. This issue affects some unknown processing of the component Optimizer. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2020-14773. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle MySQL Cluster up to 7.4.33/7.5.23/7.6.19/8.0.26. It has been classified as critical. Affected is an unknown function. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2021-35598. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 5.18.14. This affects the function dsa_port_reset_vlan_filtering. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2022-49582. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.22/6.7.10/6.8.1. It has been rated as critical. This issue affects some unknown processing of the component Bluetooth. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2024-26887. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.17-rc5. This affects the function cancel_work_sync of the file mctp-serial.c of the component MCTP Subsystem. The manipulation leads to incomplete cleanup.
This vulnerability is uniquely identified as CVE-2022-0646. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Mozilla Firefox up to 84.x. It has been classified as problematic. Affected is an unknown function of the component Pointer Lock Handler. The manipulation leads to clickjacking.
This vulnerability is traded as CVE-2021-23955. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Mozilla Firefox up to 112 and classified as critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2023-32216. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Xen and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to use after free.
This vulnerability is known as CVE-2021-28691. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic has been found in Linux Kernel up to 6.7.6. This affects an unknown part of the component gadget. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-27405. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 5.10.42/5.12.9. Affected is the function kthread_stop of the component xen-netback. The manipulation leads to use after free.
This vulnerability is traded as CVE-2021-47111. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.15.144/6.1.52/6.4/6.4.15 and classified as problematic. Affected by this issue is the function init_smb2_rsp_hdr of the component ksmbd. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2023-52441. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component com.macro.mall.portal.controller. The manipulation of the argument orderId leads to authorization bypass.
The identification of this vulnerability is CVE-2025-8755. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.