Show filters
1,622 Total Results
Displaying 101-110 of 1,622
Sort by:
Attacker Value
Unknown

CVE-2024-1153

Disclosure Date: June 27, 2024 (last updated September 17, 2024)
Improper Access Control vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68.
Attacker Value
Unknown

CVE-2024-6295

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
Attacker Value
Unknown

CVE-2024-6294

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
Attacker Value
Unknown

CVE-2024-32918

Disclosure Date: June 13, 2024 (last updated August 17, 2024)
Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps
Attacker Value
Unknown

CVE-2024-38280

Disclosure Date: June 13, 2024 (last updated October 04, 2024)
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
Attacker Value
Unknown

CVE-2024-38279

Disclosure Date: June 13, 2024 (last updated October 04, 2024)
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
Attacker Value
Unknown

CVE-2024-5559

Disclosure Date: June 12, 2024 (last updated August 24, 2024)
CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.
Attacker Value
Unknown

CVE-2024-0160

Disclosure Date: June 12, 2024 (last updated September 26, 2024)
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
Attacker Value
Unknown

CVE-2024-36821

Disclosure Date: June 11, 2024 (last updated August 17, 2024)
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
Attacker Value
Unknown

CVE-2024-27819

Disclosure Date: June 10, 2024 (last updated June 28, 2024)
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.