Vulnerabilities (CVE)

Filtered by CWE-125
Total 9747 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38649 1 Ivanti 1 Connect Secure 2026-06-17 N/A 7.5 HIGH
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-38585 1 Linux 1 Linux Kernel 2026-06-17 N/A 7.1 HIGH
In the Linux kernel, the following vulnerability has been resolved: tools/nolibc/stdlib: fix memory error in realloc() Pass user_p_len to memcpy() instead of heap->len to prevent realloc() from copying an extra sizeof(heap) bytes from beyond the allocated region.
CVE-2024-38560 1 Linux 1 Linux Kernel 2026-06-17 N/A 7.1 HIGH
In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel buffer and copy nbytes from userspace to that buffer. Later, we use sscanf on this buffer but we don't ensure that the string is terminated inside the buffer, this can lead to OOB read when using sscanf. Fix this issue by using memdup_user_nul instead of memdup_user.
CVE-2024-38481 1 Dell 1 Emc Idrac Service Module 2026-06-17 N/A 4.8 MEDIUM
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
CVE-2024-38417 1 Qualcomm 112 Ar8035, Ar8035 Firmware, C-v2x 9150 and 109 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure while processing IO control commands.
CVE-2024-38416 1 Qualcomm 144 Ar8035, Ar8035 Firmware, C-v2x 9150 and 141 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure during audio playback.
CVE-2024-38414 1 Qualcomm 58 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 55 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure while processing information on firmware image during core initialization.
CVE-2024-38405 1 Qualcomm 198 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 195 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while processing the CU information from RNR IE.
CVE-2024-38404 1 Qualcomm 80 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 77 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
CVE-2024-38403 1 Qualcomm 156 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 153 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing BTM ML IE when per STA profile is not included.
CVE-2024-38397 1 Qualcomm 232 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 229 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing probe response and assoc response frame.
CVE-2024-38389 2026-06-17 N/A 7.8 HIGH
There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
CVE-2024-38382 1 Openatom 1 Openharmony 2026-06-17 N/A 5.5 MEDIUM
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-38373 1 Amazon 1 Freertos-plus-tcp 2026-06-17 N/A 9.6 CRITICAL
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actual domain name length, could cause the parser to read beyond the DNS response buffer. This issue affects applications using DNS functionality of the FreeRTOS-Plus-TCP stack. Applications that do not use DNS functionality are not affected, even when the DNS functionality is enabled. This vulnerability has been patched in version 4.1.1.
CVE-2024-38214 1 Microsoft 6 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 3 more 2026-06-17 N/A 6.5 MEDIUM
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2024-38210 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 7.8 HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-38184 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-06-17 N/A 7.8 HIGH
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-38155 1 Microsoft 7 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 4 more 2026-06-17 N/A 5.5 MEDIUM
Security Center Broker Information Disclosure Vulnerability
CVE-2024-38151 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-06-17 N/A 5.5 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVE-2024-38148 1 Microsoft 6 Windows 11 21h2, Windows 11 22h2, Windows 11 23h2 and 3 more 2026-06-17 N/A 7.5 HIGH
Windows Secure Channel Denial of Service Vulnerability