Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

697 CVEs tagged with CWE-36727 Critical, 353 High, 270 Medium, 47 Low, 0 Unrated.

CVE-2023-22883

Published Mar 16, 2023

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23520

Published Feb 27, 2023

A race condition was addressed with additional validation. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-32477

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FvbServicesRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU rac…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32475

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-c…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32469

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the PnpSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition iss…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32953

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the SdHostDriver buffer used by SMM and non-SMM code could cause TOCTOU race-condition issu…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32476

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32473

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the HddPassword shared buffer used by SMM and non-SMM code could cause TOCTOU race-conditio…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32470

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FwBlockServiceSmm shared buffer used by SMM and non-SMM code could cause TOCTOU race-co…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32955

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the NvmExpressDxe buffer used by SMM and non-SMM code could cause TOCTOU race-condition iss…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32954

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 5.5. DMA attacks on the SdMmcDevice buffer used by SMM and non-SMM code could cause TOCTOU race-condition issue…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32478

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the IdeBusDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32474

Published Feb 15, 2023

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the StorageSecurityCommandDxe shared buffer used by SMM and non-SMM code could cause TOCTOU…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32471

Published Feb 15, 2023

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and output data. By modifying the co…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 697 CVEsPage 20 of 28