Show filters
1,505 Total Results
Displaying 231-240 of 1,505
Sort by:
Attacker Value
Unknown
CVE-2024-0048
Disclosure Date: March 11, 2024 (last updated December 18, 2024)
In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-0046
Disclosure Date: March 11, 2024 (last updated December 18, 2024)
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-0045
Disclosure Date: March 11, 2024 (last updated December 18, 2024)
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-0044
Disclosure Date: March 11, 2024 (last updated January 28, 2025)
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-0039
Disclosure Date: March 11, 2024 (last updated January 05, 2025)
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-20833
Disclosure Date: March 05, 2024 (last updated February 11, 2025)
Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.
0
Attacker Value
Unknown
CVE-2024-20836
Disclosure Date: March 05, 2024 (last updated February 11, 2025)
Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.
0
Attacker Value
Unknown
CVE-2024-20835
Disclosure Date: March 05, 2024 (last updated February 11, 2025)
Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.
0
Attacker Value
Unknown
CVE-2024-20834
Disclosure Date: March 05, 2024 (last updated February 11, 2025)
The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.
0
Attacker Value
Unknown
CVE-2024-20832
Disclosure Date: March 05, 2024 (last updated February 11, 2025)
Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
0