Tagged “nvd”
CVEs tagged nvd, newest first.
29853 CVEsRSS
CVE-2026-56879Medium· 6.7In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy
In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-55366Critical· 9.8In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code
In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for …
CVE-2026-56892Medium· 6.2In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check
In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f…
CVE-2026-56888Medium· 6.2In multiple locations, there is a possible permission bypass due to side channel information disclosure
In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for …
CVE-2026-56882High· 8.8In Cellular Modem, there is a possible information disclosure due to a logic error in the code
In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56907Medium· 6.7In VPU, there is a possible shared memory overwrite due to improper input validation
In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56889Medium· 6.7In multiple locations, there is a possible permission bypass due to an integer overflow
In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56920High· 8.8In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code
In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not nee…
CVE-2026-56915Medium· 6.4In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition
In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56914High· 8.4In multiple locations, there is a possible use-after-free due to improper locking
In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56964Medium· 6.4In multiple locations, there is a possible use-after-free due to a race condition
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56923Medium· 6.4In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition
In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for …
CVE-2026-56922Medium· 6.7In CPM, there is a possible permission bypass due to a confused deputy
In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56942High· 8.8In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check
In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed…
CVE-2026-56941High· 8.4In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code
In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
CVE-2026-56932Medium· 6.7In Trusted Execution Environment, there is a possible memory corruption due to improper input validation
In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi…
CVE-2026-56958Medium· 5.5In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check
In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n…
CVE-2026-56945High· 7.8In VPU, there is a possible out-of-bounds write due to a confused deputy
In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56967High· 8.0In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exp…
CVE-2026-56960Critical· 9.8In multiple locations, there is a possible use-after-free due to a logic error in the code
In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56950Medium· 4.4In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation
In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for …
CVE-2026-56973Medium· 6.7In multiple locations, there is a possible escalation of privilege due to a logic error in the code
In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56972Medium· 6.7In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check
In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56970High· 8.4In multiple locations, there is a possible permission bypass due to a missing permission check
In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat…
CVE-2026-56978High· 8.4In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check
In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
CVE-2026-56975Medium· 6.5In Cellular Modem, there is a possible denial of service due to improper input validation
In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for…
CVE-2026-56974High· 8.8In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation
In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for…
CVE-2026-56986High· 8.4In multiple files, there is a possible out-of-bounds read due to type confusion
In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56982High· 7.8In VPU, there is a possible permission bypass due to a missing permission check
In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-56979Medium· 6.7In multiple locations, there is a possible permission bypass due to a logic error in the code
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.