CVE-2024-8189
Sáb, 28/09/2024 – 13:15
CVE-2024-8189
CVE-2024-8189
Sáb, 28/09/2024 – 13:15
CVE-2024-8189
CVE-2024-9296
Sáb, 28/09/2024 – 09:15
CVE-2024-9296
CVE-2024-8712
Sáb, 28/09/2024 – 09:15
CVE-2024-8712
CVE-2024-23957
Sáb, 28/09/2024 – 06:15
CVE-2024-23957
The specific flaw exists within the DLB_HostHeartBeat handler of the DLB protocol implementation. When parsing an AES key, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
Was ZDI-CAN-23241
CVE-2024-23935
Sáb, 28/09/2024 – 07:15
CVE-2024-23935
The specific flaw exists within the DecodeUTF7 function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.
Was ZDI-CAN-23249
CVE-2024-23924
Sáb, 28/09/2024 – 07:15
CVE-2024-23924
The specific flaw exists within the UPDM_wemCmdCreatSHA256Hash function. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Was ZDI-CAN-23105
CVE-2024-23923
Sáb, 28/09/2024 – 07:15
CVE-2024-23923
The specific flaw exists within the prh_l2_sar_data_ind function. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root.
Was ZDI-CAN-22945
CVE-2024-23967
Sáb, 28/09/2024 – 07:15
CVE-2024-23967
The specific flaw exists within the handling of base64-encoded data within WebSocket messages. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
Was ZDI-CAN-23230
CVE-2024-23961
Sáb, 28/09/2024 – 07:15
CVE-2024-23961
The specific flaw exists within the UPDM_wemCmdUpdFSpeDecomp function. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Was ZDI-CAN-23306
CVE-2024-23960
Sáb, 28/09/2024 – 07:15
CVE-2024-23960
The specific flaw exists within the firmware metadata signature validation mechanism. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.
Was ZDI-CAN-23102