CVE-2015-4422
published 2017-10-19CVE-2015-4422: The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root permissions to gain privileges or cause a…
PriorityP426high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
0.64%
46.4th percentile
The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root permissions to gain privileges or cause a denial of service (memory corruption) via a crafted application.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | mate_7_firmware | <= v100r001chnc00b123sp03 | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
arXiv
Enclave-Aware Compartmentalization and Secure Sharing with Sirius
arxiv_fulltext·2020-11-23
Enclave-Aware Compartmentalization and Secure Sharing with Sirius
Enclave-Aware Compartmentalization and Secure Sharing with Sirius
Zahra Tarkhani
University of Cambridge
Anil Madhavapeddy
University of Cambridge
## Abstract
Hardware-assisted trusted execution environments (TEEs) are critical building blocks of many modern applications. However, they have a one-way isolation model that introduces a semantic gap between a TEE and its outside world. This lack of information causes an ever-increasing set of attacks on TEE-enabled applications that exploit various insecure interactions with the host OSs, applications, or other enclaves.
We introduce Sirius, the first compartmentalization framework that achieves strong isolation and secure sharing in TEE-assisted applications by controlling the dataflows within primary kernel objects (e.g. threads, proc
Bugzilla
CVE-2015-3427 quassel: SQL injection flaw (incomplete fix for CVE-2013-4422)
bugzilla·2015-04-28·CVSS 6.8
CVE-2015-3427 [MEDIUM] CVE-2015-3427 quassel: SQL injection flaw (incomplete fix for CVE-2013-4422)
CVE-2015-3427 quassel: SQL injection flaw (incomplete fix for CVE-2013-4422)
It was discovered that the fix for CVE-2013-4422 was incomplete and did not fix the original SQL injection on reconnection issue.
Upstream patch:
https://github.com/quassel/quassel/commit/6605882f41331c80f7ac3a6992650a702ec71283
Fixed version:
http://quassel-irc.org/node/120
Discussion:
Created quassel tracking bugs for this issue:
Affects: fedora-all [bug 1216076]
Affects: epel-6 [bug 1216077]
Affects: epel-7 [bug 1216078]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
2017-10-19
Published