CVE-2025-47396
Published Jan 7, 2026Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Year archive
43,229 CVEs published in 2026 — 4,572 Critical, 17,154 High, 17,412 Medium, 3,603 Low, 488 Unrated.
Memory corruption occurs when a secure application is launched on a device with insufficient memory.
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.
Memory corruption when accessing resources in kernel driver.
Memory corruption while passing pages to DSP with an unaligned starting address.
Memory corruption while preprocessing IOCTLs in sensors.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory Corruption when multiple threads concurrently access and modify shared resources.
Memory corruption while processing identity credential operations in the trusted application.
Memory corruption while processing a secure logging command in the trusted application.
Cryptographic issue may occur while encrypting license data.
Memory corruption while handling sensor utility operations.
Memory corruption while processing a video session to set video parameters.
Memory corruption while deinitializing a HDCP session.
Memory corruption while accessing a synchronization object during concurrent operations.
Memory corruption while performing sensor register read operations.
Memory corruption while parsing clock configuration data for a specific hardware type.
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Memory corruption while processing a config call from userspace.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects…
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of adm…
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configurat…