Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2022
Memory corruption in graphics due to buffer overflow while validating the user address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVSS Score
8.4
EPSS Score
0.001
Published
2022-11-15
Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
CVSS Score
9.8
EPSS Score
0.002
Published
2022-11-15
Denial of service in MODEM due to reachable assertion in Snapdragon Mobile
CVSS Score
7.5
EPSS Score
0.002
Published
2022-11-15
Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking
CVSS Score
7.5
EPSS Score
0.002
Published
2022-11-15
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
CVSS Score
6.1
EPSS Score
0.377
Published
2022-11-15
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
CVSS Score
7.8
EPSS Score
0.003
Published
2022-11-15
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.
CVSS Score
7.8
EPSS Score
0.003
Published
2022-11-15
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVSS Score
9.8
EPSS Score
0.006
Published
2022-11-15
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-11-15
In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-11-15


Contact Us

Shodan ® - All rights reserved