Show filters
1,625 Total Results
Displaying 491-500 of 1,625
Sort by:
Attacker Value
Unknown

CVE-2022-1745

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker with physical access may use this to gain administrative privileges on a device and install malicious code or perform arbitrary administrative actions.
Attacker Value
Unknown

CVE-2022-1744

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.
Attacker Value
Unknown

CVE-2022-1743

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leverage this vulnerability to spread malicious code to ImageCast X devices from the EMS.
Attacker Value
Unknown

CVE-2022-1742

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.
Attacker Value
Unknown

CVE-2022-1741

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code.
Attacker Value
Unknown

CVE-2022-1740

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestation mechanisms. An attacker could leverage this vulnerability to disguise malicious applications on a device.
Attacker Value
Unknown

CVE-2022-1739

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the manufacturer to detect tampering. An attacker could leverage this vulnerability to install malicious code, which could also be spread to other vulnerable ImageCast X devices via removable media.
Attacker Value
Unknown

CVE-2022-33953

Disclosure Date: June 22, 2022 (last updated October 07, 2023)
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.
Attacker Value
Unknown

CVE-2022-20132

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
In lg_probe and related functions of hid-lg.c and other USB HID files, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if a malicious USB HID device were plugged in, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-188677105References: Upstream kernel
Attacker Value
Unknown

CVE-2022-20125

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-194402515