Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Integer Overflow or Wraparound in Graphics

Memory corruption while using alignments for memory allocation.

CWE-190Mar 2, 2026
CVSS7.8v3.1EPSS1.07%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Incorrect Authorization in Graphics

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

CWE-863Jun 3, 2025
CVSS8.6v3.1EPSS0.778%PoCs4SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Graphics

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

CWE-416Jun 3, 2025
CVSS7.5v3.1EPSS0.831%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Incorrect Authorization in Graphics Windows

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

CWE-863Jun 3, 2025
CVSS8.6v3.1EPSS0.435%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Validation of Array Index in WLAN Host Communication

Memory corruption while parsing the ML IE due to invalid frame content.

CWE-129Feb 3, 2025
CVSS9.8v3.1EPSS0.485%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows Host

Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.

CWE-119CWE-787Dec 2, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Video Analytics and Processing

Memory corruption while processing API calls to NPU with invalid input.

CWE-20Dec 2, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stack-based Buffer Overflow in WLAN Windows Host

Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.

CWE-121CWE-787Dec 2, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Restriction of Operations within the Bounds of a Memory Buffer in WLAN Windows Host

Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.

CWE-119CWE-787Dec 2, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Stack-based Buffer Overflow in Performance

Memory corruption when invalid input is passed to invoke GPU Headroom API call.

CWE-121CWE-787Dec 2, 2024
CVSS7.8v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Integer Overflow or Wraparound in WLAN Host Communication

Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.

CWE-190Dec 2, 2024
CVSS7.5v3.1EPSS0.265%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in MProc

Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

CWE-125CWE-126Dec 2, 2024
CVSS8.4v3.1EPSS0.104%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Video

Memory corruption when multiple threads try to unregister the CVP buffer at the same time.

CWE-416Dec 2, 2024
CVSS6.7v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Validation of Array Index in Hypervisor

Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

CWE-129Dec 2, 2024
CVSS8.4v3.1EPSS0.104%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Camera Driver

Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.

CWE-416Dec 2, 2024
CVSS6.7v3.1EPSS0.089%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Untrusted Pointer Dereference in Audio

Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.

CWE-822Dec 2, 2024
CVSS6.7v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in Neural Processing Unit

Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.

CWE-126Dec 2, 2024
CVSS6.1v3.1EPSS0.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use of Out-of-range Pointer Offset in Camera Driver

Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.

CWE-823Dec 2, 2024
CVSS6.7v3.1EPSS0.103%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Buffer Over-read in IPA

An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'

CWE-126CWE-191Nov 26, 2024
CVSS8.4v3.1EPSS0.115%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Use After Free in Video

Crafted Binder Request Causes Heap UAF in MediaServer

CWE-416Nov 26, 2024
CVSS7.8v3.1EPSS0.111%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Information Exposure in Kernel

Information disclosure possible while audio playback.

CWE-200Nov 26, 2024
CVSS8.4v3.1EPSS0.114%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Information Exposure in Camera Driver

Information disclosure due to uninitialized variable.

CWE-200CWE-908Nov 26, 2024
CVSS8.4v3.1EPSS0.114%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Access Control in Core.

QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.

CWE-284Nov 26, 2024
CVSS7.8v3.1EPSS0.105%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Audio

Possible out of bound access in audio module due to lack of validation of user provided input.

CWE-20Nov 22, 2024
CVSS6.7v3.1EPSS0.123%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Permissions, Privileges, and Access Controls in Data

Certain unprivileged processes are able to perform IOCTL calls.

CWE-264Nov 22, 2024
CVSS6.7v3.1EPSS0.117%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX