Page 2 of 32 results (0.011 seconds)

CVSS: 7.8EPSS: 8%CPEs: 2EXPL: 2

01 Jun 2023 — In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition. • https://github.com/lan1oc/CVE-2023-34312-exp • CWE-763: Release of Invalid Pointer or Reference •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

26 Apr 2023 — vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts. • https://cwe.mitre.org/data/definitions/1321.html • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

03 Aug 2022 — A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script. Una vulnerabilidad en el analizador lua de TscanCode tsclua versión v2.15.01, permite a atacantes causar una Denegación de Servicio (DoS) por medio de un script lua diseñado • https://github.com/Tencent/TscanCode/issues/65 •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 1

26 Jul 2022 — The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center. La aplicación QQ versión 8.7.1 para Android e iOS no aplica los requisi... • https://arxiv.org/pdf/2205.15202.pdf • CWE-862: Missing Authorization •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 3

26 Jul 2022 — In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts. En la aplicación WeChat versión 8.0.10 para Android e iOS, un mini programa puede obtener información confidencial de la libreta de direcciones de un usuario por medio de wx.searchContacts • https://arxiv.org/pdf/2205.15202.pdf • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

03 May 2022 — TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. TencentOS-tinyv versión 3.1.0, es vulnerable a una envoltura de enteros en el cálculo incorrecto de la función "tos_mmheap_alloc del tamaño efectivo de asignación de memoria. Esta asignación de mem... • https://www.cisa.gov/uscert/ics/advisories/icsa-21-119-04 • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 1

06 Jun 2021 — Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a download URL with one pointing to an arbitrary Windows executable. Because the only integrity check would be a comparison of the downloaded file's MD5 checksum to the one contained within the XML document, the downloaded executable would then be executed on the victim's machine. Tencent GameLoop v... • https://github.com/mmiszczyk/cve-2021-33879 • CWE-494: Download of Code Without Integrity Check •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

24 Feb 2021 — This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat 2.9.5 desktop version. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM decoder. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction w... • https://www.zerodayinitiative.com/advisories/ZDI-21-217 • CWE-125: Out-of-bounds Read •

CVSS: 8.8EPSS: 1%CPEs: 1EXPL: 0

22 Jan 2021 — This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM Decoder. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated object. An attacker can leverage this vulnerability to execute code ... • https://www.zerodayinitiative.com/advisories/ZDI-21-084 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

03 Sep 2020 — The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code. La aplicación Shenzhen Tencent versión 5.8.2.5300 para plataformas de PC (de Tencent App Center) presenta una vulnerabilidad de secuestro de DLL. Los atacantes pueden usar esta vulnerabilidad para ejecutar código malicioso • https://www.cnvd.org.cn/flaw/show/2105399 • CWE-427: Uncontrolled Search Path Element •