Show filters
2,035 Total Results
Displaying 21-30 of 2,035
Sort by:
Attacker Value
Unknown

CVE-2025-20639

Disclosure Date: February 03, 2025 (last updated February 05, 2025)
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2060.
Attacker Value
Unknown

CVE-2025-20638

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291449; Issue ID: MSV-2066.
Attacker Value
Unknown

CVE-2025-20636

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09403554; Issue ID: MSV-2431.
Attacker Value
Unknown

CVE-2025-20635

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09403752; Issue ID: MSV-2434.
Attacker Value
Unknown

CVE-2024-20142

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291406; Issue ID: MSV-2070.
Attacker Value
Unknown

CVE-2024-20141

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291402; Issue ID: MSV-2073.
Attacker Value
Unknown

CVE-2024-49415

Disclosure Date: December 03, 2024 (last updated February 11, 2025)
Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-49414

Disclosure Date: December 03, 2024 (last updated February 11, 2025)
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
Attacker Value
Unknown

CVE-2024-49411

Disclosure Date: December 03, 2024 (last updated February 11, 2025)
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
Attacker Value
Unknown

CVE-2024-49410

Disclosure Date: December 03, 2024 (last updated February 11, 2025)
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.