Show filters
1,503 Total Results
Displaying 41-50 of 1,503
Sort by:
Attacker Value
Unknown

CVE-2023-40529

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information.
Attacker Value
Unknown

CVE-2024-20666

Disclosure Date: January 09, 2024 (last updated January 15, 2024)
BitLocker Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-5138

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.
Attacker Value
Unknown

CVE-2023-5879

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials.
Attacker Value
Unknown

CVE-2023-33014

Disclosure Date: January 02, 2024 (last updated February 17, 2024)
Information disclosure in Core services while processing a Diag command.
Attacker Value
Unknown

CVE-2023-52275

Disclosure Date: December 31, 2023 (last updated January 12, 2024)
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.
Attacker Value
Unknown

CVE-2023-4468

Disclosure Date: December 29, 2023 (last updated January 09, 2024)
A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-4467

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249260.
Attacker Value
Unknown

CVE-2023-49228

Disclosure Date: December 28, 2023 (last updated January 05, 2024)
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
Attacker Value
Unknown

CVE-2023-46918

Disclosure Date: December 27, 2023 (last updated January 06, 2024)
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.