Show filters
1,505 Total Results
Displaying 241-250 of 1,505
Sort by:
Attacker Value
Unknown

CVE-2024-20831

Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-20830

Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
Attacker Value
Unknown

CVE-2023-52432

Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.
Attacker Value
Unknown

CVE-2024-20022

Disclosure Date: March 04, 2024 (last updated January 31, 2025)
In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255.
Attacker Value
Unknown

CVE-2024-20020

Disclosure Date: March 04, 2024 (last updated February 26, 2025)
In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.
Attacker Value
Unknown

CVE-2024-0023

Disclosure Date: February 16, 2024 (last updated February 26, 2025)
In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2024-0021

Disclosure Date: February 16, 2024 (last updated February 26, 2025)
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2024-0020

Disclosure Date: February 16, 2024 (last updated December 18, 2024)
In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2024-0019

Disclosure Date: February 16, 2024 (last updated January 04, 2025)
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2024-0018

Disclosure Date: February 16, 2024 (last updated February 26, 2025)
In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.