Show filters
155 Total Results
Displaying 31-40 of 155
Sort by:
Attacker Value
Unknown
CVE-2022-23470
Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects Galaxy 22.01 and higher, after the switch to gunicorn, which serve static contents directly. Additionally, the vulnerability is mitigated when using Nginx or Apache to serve /static/* contents, instead of Galaxy's internal middleware. This issue has been patched in commit `e5e6bda4f` and will be included in future releases. Users are advised to manually patch their installations. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2022-39893
Disclosure Date: November 09, 2022 (last updated December 22, 2024)
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.
0
Attacker Value
Unknown
CVE-2022-39889
Disclosure Date: November 09, 2022 (last updated December 22, 2024)
Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.
0
Attacker Value
Unknown
CVE-2022-36875
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
0
Attacker Value
Unknown
CVE-2022-36874
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.
0
Attacker Value
Unknown
CVE-2022-36873
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.
0
Attacker Value
Unknown
CVE-2022-31262
Disclosure Date: August 17, 2022 (last updated February 24, 2025)
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in code execution as SYSTEM.
0
Attacker Value
Unknown
CVE-2022-36838
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.
0
Attacker Value
Unknown
CVE-2022-33710
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
0
Attacker Value
Unknown
CVE-2022-33709
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
0