Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-02 CVE-2018-9413 Out-of-bounds Write vulnerability in Google Android
In handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2024-12-02 CVE-2018-9414 Out-of-bounds Write vulnerability in Google Android
In gattServerSendResponseNative of com_android_bluetooth_gatt.cpp, there is a possible out of bounds stack write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2024-12-02 CVE-2018-9380 Out-of-bounds Write vulnerability in Google Android
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to improper input validation.
network
low complexity
google CWE-787
8.8
2024-12-02 CVE-2018-9381 Use of Uninitialized Resource vulnerability in Google Android 8.1
In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data.
network
low complexity
google CWE-908
7.5
2024-12-02 CVE-2024-46905 Unspecified vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.
network
low complexity
progress
8.8
2024-12-02 CVE-2024-46906 Unspecified vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
network
low complexity
progress
8.8
2024-12-02 CVE-2024-46907 Unspecified vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
network
low complexity
progress
8.8
2024-12-02 CVE-2024-46908 Unspecified vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
network
low complexity
progress
8.8
2024-12-02 CVE-2024-53108 Out-of-bounds Read vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Adjust VSDB parser for replay feature At some point, the IEEE ID identification for the replay check in the AMD EDID was added.
local
low complexity
linux CWE-125
7.1
2024-12-02 CVE-2024-33040 Unspecified vulnerability in Qualcomm products
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
local
high complexity
qualcomm
7.0