CVE-2022-38696
- EPSS 0.09%
- Published 01.09.2025 07:28:15
- Last modified 02.09.2025 15:55:25
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
CVE-2022-38695
- EPSS 0.02%
- Published 01.09.2025 07:28:14
- Last modified 02.09.2025 15:55:25
In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additional execution privileges needed.
CVE-2022-38694
- EPSS 0.34%
- Published 01.09.2025 07:28:13
- Last modified 02.09.2025 15:55:25
In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed.
CVE-2022-38693
- EPSS 0.09%
- Published 01.09.2025 07:28:12
- Last modified 02.09.2025 15:55:25
In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
CVE-2022-38692
- EPSS 0.07%
- Published 01.09.2025 07:28:11
- Last modified 02.09.2025 15:55:25
In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without requiring additional execution privileges.
CVE-2022-38691
- EPSS 0.16%
- Published 01.09.2025 07:28:10
- Last modified 02.09.2025 15:55:25
In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed.
CVE-2025-31716
- EPSS 0.02%
- Published 01.08.2025 05:55:00
- Last modified 04.08.2025 15:06:15
In bootloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.
CVE-2025-31712
- EPSS 0.01%
- Published 03.06.2025 05:50:53
- Last modified 10.06.2025 15:15:48
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.
CVE-2025-31711
- EPSS 0.01%
- Published 03.06.2025 05:50:52
- Last modified 10.06.2025 15:15:41
In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional execution privileges needed.
CVE-2024-39442
- EPSS 0.02%
- Published 06.05.2025 01:07:27
- Last modified 07.05.2025 14:13:35
In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed.