събота, 26 септември 2020 г.

Weekly Update: a new vulnerability is published on the National Vulnerability Database (44 items)


New vulnerabilities from the NVD: CVE-2020-11118

u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QCS610, QM215, Rennell, Saipan, SC8180X, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-11117

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-11116

u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QCS610, QM215, SA6155P, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-11115

u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from beacon' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM660, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14119

u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition and lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, Kamorta, MDM9205, MDM9607, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDM670, SDM710, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14117

u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which results in a use after free causing an unhandled page fault exception in rmnet driver' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, MDM9607, QCS405, Saipan, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14115

u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result in user reading the secure input while touch is in non-secure domain as secure display is active' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14089

u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, Nicobar, QCS404, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14074

u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2 130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14065

u'Pointer double free in HavenSvc due to not setting the pointer to NULL after freeing it' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8998, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14056

u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9150, MDM9205, MDM9607, MDM9650, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14052

u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QCS610, QM215, SA415M, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-14025

u'When a new session is created, Object is returned that contains TZ addresses and it get passed to HLOS as an handle to refer to a particular session and can cause TZ to jump to a invalid address' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, QCS610, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-13999

u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-13998

u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6 150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-13995

u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7 150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-13994

u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than the actual packet size can lead to memory corruption and potential information leakage' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, S DM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-13992

u'Out of bound memory access if stack push and pop operation are performed without doing a bound check on stack top' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, IPQ6018, IPQ8074, MDM9205, Nicobar, QCA8081, QCN7605, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10629

u'User Process can potentially corrupt kernel virtual page by passing a crafted page in API' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, IPQ6018, IPQ8074, MDM9205, Nicobar, QCA8081, QCN7605, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10628

u'Memory can be potentially corrupted if random index is allowed to manipulate TLB entries in Kernel from user library' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8098, Bitra, MDM9205, MDM9650, MSM8998, Nicobar, QCA6390, QCN7605, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10615

u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of keymaster bob which can lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10596

u'Improper access control can lead signed process to guess pid of other processes and access their address space' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Bitra, Nicobar, QCS605, QCS610, Rennell, SA6155P, Saipan, SC7180, SC8180X, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10562

u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ6018, Kamorta, MSM8998, Nicobar, QCS404, QCS605, QCS610, Rennell, SA415M, SA6155P, SC7180, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10527

u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range which could lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA4531, QCA6574AU, QCA8081, QCM2150, QCN7605, QCN7606, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850 , SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-13903

u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, MDM9205, MDM9206, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, SDM450, SM8150
Published at: September 08, 2020 at 01:15PM
View on website

September 08, 2020 at 03:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-11124

u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCS404, QCS405, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM660, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Published at: September 09, 2020 at 10:15AM
View on website

September 09, 2020 at 01:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17774

Ingenico Telium 2 POS terminals have an insecure NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17773

Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17772

Ingenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17771

Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17770

Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17769

Ingenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17768

Ingenico Telium 2 POS terminals have an insecure TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17767

Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17766

Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17765

Ingenico Telium 2 POS terminals have undeclared TRACE protocol commands. This is fixed in Telium 2 SDK v9.32.03 patch N.
Published at: September 09, 2020 at 10:15PM
View on website

September 09, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-17145

Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Published at: September 10, 2020 at 08:15PM
View on website

September 10, 2020 at 09:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2014-1420

On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink restrictions in Ubuntu. Fixed in 1.1.1188+14.10.20140813.4-0ubuntu1.
Published at: September 11, 2020 at 03:15AM
View on website

September 11, 2020 at 08:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-19948

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Published at: September 11, 2020 at 06:15PM
View on website

September 11, 2020 at 07:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-19947

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Published at: September 11, 2020 at 06:15PM
View on website

September 11, 2020 at 07:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-19946

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Published at: September 11, 2020 at 06:15PM
View on website

September 11, 2020 at 07:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2014-10401

An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
Published at: September 11, 2020 at 10:15PM
View on website

September 11, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2013-7491

An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.
Published at: September 11, 2020 at 10:15PM
View on website

September 11, 2020 at 11:36PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2013-7490

An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
Published at: September 11, 2020 at 10:15PM
View on website

September 11, 2020 at 11:36PM

via National Vulnerability Database


петък, 25 септември 2020 г.

Филми по Карел Чапек в Чешкия център и




Чешки филми на София Филм Фест

http://sofia.czechcentres.cz/

Филм
Сърдечно ви каним на прожекците на филми по мотиви на Карел Чапек в Чешкия център. Програмата е: 30.9., 18:30 ч., „Бялата болест"; 1.10., 18:30 ч., „Хордубал"; 2.10., 18:30 ч., „Кракатит". Филмите са на чешки със субтитри на български. Входът е свободен.

Обръщаме внимание и на заглавията с чешка копродукция в есенното издание на София Филм Фест.

Филм

Съпътстваща програма към София Филм Фест ЕСЕН: Филми по Карел Чапек

30. 9. 2020 - 2. 10. 2020
Rakovski 100, 1000 Sofia

Филми по мотиви от творби на Карел Чапек ще бъдат прожектирани в Чешкия център в рамките на София Филм Фест 2020. Прожекциите са част от програмата, с която отбелязваме 130 години от рождението на световноизвестния чешки писател Карел Чапек и 100 години от появата на думата „робот".

Повече на: ČC Sofie

Нагоре

Чешкото участие на София Филм Фест ЕСЕН

24. 9. 2020 - 15. 10. 2020

Заглавия с чешка копродукция в есенното издание на фестивала: "Боядисаната птица" (2019), "Шарлатан" 2020), "Соло" (2019), "Свидетелите на Путин" (2018), "Под слънцето" (2015), Cook F**k Kill (2019). В рамките на СОФИЯ ФИЛМ ФЕСТ ЕСЕН в Чешки център София ще представим програма с филми по мотиви на Карел Чапек.

Повече на: ČC Sofie

Нагоре

Редактор: Чешки център
Контакт: София 1000


Weekly Update: New diabetes clinical trial (7 items)



New diabetes clinical trial: NBT-NM108 as an Early Treatment of Suspected or Confirmed COVID-19 in Patients With Prediabetes or Type 2 Diabetes

Published on: September 07, 2020 at 07:00PM
Condition:   Suspected or Confirmed COVID-19
Interventions:   Drug: NBT-NM108;   Other: Usual Care Only
Sponsors:   Notitia Biotechnologies Company;   University of South Florida;   Rutgers University
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04540406?term=diabetes&sfpd_d=14 September 08, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Feasibility and Effectiveness of Real-time, Remote Continuous Glucose Monitoring in Adolescents With Poorly Controlled Type 1 Diabetes

Published on: September 07, 2020 at 07:00PM
Conditions:   Diabetes Mellitus, Type 1;   Noncompliance, Patient
Interventions:   Other: Continuous Glucose Monitoring;   Other: Secure texting
Sponsors:   University of Texas Southwestern Medical Center;   DexCom, Inc.
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04540536?term=diabetes&sfpd_d=14 September 08, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Impact of the Type of Reconstruction Methods on Diabetes Following Laparoscopic Distal Gastrectomy in Patients With Gastric Cancer and Type 2 Diabetes

Published on: September 07, 2020 at 07:00PM
Conditions:   Stomach Neoplasms;   Diabetes Mellitus, Type 2
Interventions:   Procedure: conventional BI;   Procedure: long-limb BII;   Procedure: long-limb RY group
Sponsors:   Kyungpook National University Chilgok Hospital;   Kyungpook National University Hospital
Completed
https://clinicaltrials.gov/ct2/show/NCT04539769?term=diabetes&sfpd_d=14 September 08, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Glycemic Control After Antenatal Corticosteroids in Women With Pregestational Diabetes

Published on: September 09, 2020 at 07:00PM
Conditions:   Diabetes Mellitus, Type 2;   Preterm Birth;   Pregnancy, High Risk
Interventions:   Drug: Sliding Scale Insulin;   Drug: Up-Titration of Home Insulin;   Drug: Continuous Insulin Infusion;   Device: Dexcom G6 Professional Continuous Glucose Monitor
Sponsor:   University of Alabama at Birmingham
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04542148?term=diabetes&sfpd_d=14 September 09, 2020 at 03:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Verapamil SR in Adults With Type 1 Diabetes

Published on: September 10, 2020 at 07:00PM
Condition:   Diabetes Mellitus, Type 1
Interventions:   Drug: Verapamil SR;   Drug: Placebo
Sponsors:   Medical University of Graz;   Juvenile Diabetes Research Foundation
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04545151?term=diabetes&sfpd_d=14 September 10, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Combination GRA and SGLT-2i Treatment in Type 1 Diabetes

Published on: September 11, 2020 at 07:00PM
Condition:   Type 1 Diabetes
Interventions:   Drug: Dapagliflozin 10 MG [Farxiga];   Drug: REMD-477;   Drug: Placebo
Sponsors:   University of California, San Diego;   REMD Biotherapeutics, Inc.
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04545411?term=diabetes&sfpd_d=14 September 11, 2020 at 04:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Fully Automated Closed Loop Control in Adolescents With Type 1 Diabetes

Published on: September 11, 2020 at 07:00PM
Condition:   Type 1 Diabetes
Intervention:   Device: RocketAP
Sponsor:   University of Virginia
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04545567?term=diabetes&sfpd_d=14 September 11, 2020 at 04:24PM

via ClinicalTrials.gov


четвъртък, 24 септември 2020 г.

Weekly Digest: New diabetes clinical trial (15 items)


New diabetes clinical trial: The DENOCHARCOT Trial

Published on: September 14, 2020 at 07:00PM
Conditions:   Charcot Foot;   Diabetes Mellitus
Intervention:   Drug: Denosumab Injection
Sponsor:   Ole Lander Svendsen
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04547348?term=diabetes&sfpd_d=14 September 14, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: A Study to Assess the Effect of Psyllium vs. Wheat Dextrin on Glycemic Control and Inflammatory Markets in Diabetes Mellitus 2

Published on: September 14, 2020 at 07:00PM
Condition:   Type2 Diabetes
Interventions:   Dietary Supplement: Psyllium;   Dietary Supplement: Wheat Dextrin
Sponsor:   Mayo Clinic
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04547790?term=diabetes&sfpd_d=14 September 14, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Fasting Versus Fed: Effect of Oral Intake Prior to the Glucose Tolerance Test in Pregnancy

Published on: September 14, 2020 at 07:00PM
Conditions:   Gestational Diabetes;   Diagnoses Disease;   Pregnancy in Diabetic;   Glucose, High Blood
Interventions:   Behavioral: Fasting before gestational diabetes screen;   Behavioral: Per oral intake of food and drink
Sponsor:   Stanford University
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04547023?term=diabetes&sfpd_d=14 September 14, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Sleep Apnea, Subclinical Coronary Atherosclerosis and Heart Failure in Diabetes Patients With Nephropathy

Published on: September 15, 2020 at 07:00PM
Conditions:   Sleep Apnea;   Diabetic Nephropathy Type 2;   Coronary Atheroscleroses;   Heart Insufficiency;   Arterial Stiffness;   Kidney Diseases;   Vascular Diseases
Intervention:  
Sponsor:   University of Aarhus
Recruiting
https://clinicaltrials.gov/ct2/show/NCT04549324?term=diabetes&sfpd_d=14 September 15, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Clinical Phenotype and Outcomes of Inpatients With COVID-19 and Diabetes

Published on: September 15, 2020 at 07:00PM
Conditions:   Diabetes Mellitus;   Covid19
Intervention:  
Sponsor:   Azienda Ospedaliero-Universitaria di Parma
Recruiting
https://clinicaltrials.gov/ct2/show/NCT04550403?term=diabetes&sfpd_d=14 September 15, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Low-carbohydrate Versus Low-fat Breakfast in Type 2 Diabetes

Published on: September 16, 2020 at 07:00PM
Condition:   Dietary Habits
Interventions:   Other: Low-Carb High-Fat breakfast;   Other: Low fat "standard care" control breakfast
Sponsors:   University of British Columbia;   University of Wollongong
Recruiting
https://clinicaltrials.gov/ct2/show/NCT04550468?term=diabetes&sfpd_d=14 September 16, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Glycated Albumin Combined With Body Composition for Gestational Diabetes Mellitus Prediction

Published on: September 16, 2020 at 07:00PM
Condition:   Gestational Diabetes Mellitus in Pregnancy
Intervention:  
Sponsor:   Peking Union Medical College Hospital
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04550806?term=diabetes&sfpd_d=14 September 16, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Colonic Motility in Patients With Diabetes

Published on: September 16, 2020 at 07:00PM
Condition:   Diabetes Mellitus
Intervention:   Device: High Resolution Colonic Manometry and 3D-Transit system.
Sponsors:   University of Aarhus;   Aalborg University Hospital
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04551625?term=diabetes&sfpd_d=14 September 16, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Copeptin After a Subcutaneous Stimulation With Glucagon in Adults

Published on: September 16, 2020 at 07:00PM
Condition:   Diabetes Insipidus
Interventions:   Diagnostic Test: Glucagon;   Diagnostic Test: Placebo
Sponsors:   University Hospital, Basel, Switzerland;   Swiss National Science Foundation
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04550520?term=diabetes&sfpd_d=14 September 16, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Specialized Technology Education for Pumps & Pens in Underserved Populations With Diabetes

Published on: September 16, 2020 at 07:00PM
Condition:   Type1diabetes
Interventions:   Other: Education: Session 1 - Basics of type 1 management;   Other: Session 2 - Carbohydrate counting;   Other: Education: Session 3 - Insulin self- adjustment;   Other: Education: Session 4 - Sick day rules and physical activity dose adjustments;   Other: Education: Session 5 - Starting the insulin pen (for pen users) or pump (for pump users);   Other: Education: Session 6 - Trouble shooting the pump (for pump users)
Sponsors:   University of Southern California;   The Leona M. and Harry B. Helmsley Charitable Trust
Completed
https://clinicaltrials.gov/ct2/show/NCT04550585?term=diabetes&sfpd_d=14 September 16, 2020 at 02:24PM

via ClinicalTrials.gov


New diabetes clinical trial: A Study to Evaluate the Safety, Tolerability, Pharmacokinetics and Pharmacodynamics of PF-06882961 in Japanese Adults With Type 2 Diabetes Mellitus

Published on: September 17, 2020 at 07:00PM
Condition:   Type 2 Diabetes Mellitus
Interventions:   Drug: Placebo;   Drug: PF-06882961
Sponsor:   Pfizer
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04552470?term=diabetes&sfpd_d=14 September 17, 2020 at 03:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Study on the Feasibility of Community Doctors Guided by Specialists to Use Basic Insulin

Published on: September 17, 2020 at 07:00PM
Condition:   Type 2 Diabetes
Intervention:   Drug: basic insulin
Sponsor:   Shenzhen Second People's Hospital
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04553380?term=diabetes&sfpd_d=14 September 17, 2020 at 03:24PM

via ClinicalTrials.gov


New diabetes clinical trial: HSK7653 Treatment in Patients With Type 2 Diabetes Who Are Not Controlled With Diet and Exercise

Published on: September 21, 2020 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Interventions:   Drug: HSK7653 10 mg Q2W;   Drug: HSK7653 25 mg Q2W;   Drug: Placebo
Sponsor:   Sichuan Haisco Pharmaceutical Group Co., Ltd.
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04556851?term=diabetes&sfpd_d=14 September 19, 2020 at 08:24PM

via ClinicalTrials.gov


New diabetes clinical trial: ADAM17 and Vascular Function in Diabetes

Published on: September 21, 2020 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Interventions:   Dietary Supplement: Placebo;   Dietary Supplement: Phosphatidylserine
Sponsor:   University of Missouri-Columbia
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04557228?term=diabetes&sfpd_d=14 September 19, 2020 at 08:24PM

via ClinicalTrials.gov


New diabetes clinical trial: Study to Assess the Effect on Glucose Homeostasis of Two Dose Levels of AZD9567, Compared to Prednisolone, in Adults With Type 2 Diabetes

Published on: September 21, 2020 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Interventions:   Drug: AZD9567;   Drug: Prednisolone;   Other: Placebo
Sponsors:   AstraZeneca;   Parexel
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT04556760?term=diabetes&sfpd_d=14 September 19, 2020 at 08:24PM

via ClinicalTrials.gov