Show filters
1,135 Total Results
Displaying 31-40 of 1,135
Sort by:
Attacker Value
Unknown
CVE-2025-24803
Disclosure Date: February 05, 2025 (last updated February 06, 2025)
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.). However, an attacker can manually modify this value in the `Info.plist` file and add special characters to the `<key>CFBundleIdentifier</key>` value. The `dynamic_analysis.html` file does not sanitize the received bundle value from Corellium and as a result, it is possible to break the HTML context and achieve Stored XSS. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2025-20906
Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.
0
Attacker Value
Unknown
CVE-2024-49843
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
0
Attacker Value
Unknown
CVE-2024-49839
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption during management frame processing due to mismatch in T2LM info element.
0
Attacker Value
Unknown
CVE-2024-49838
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Information disclosure while parsing the OCI IE with invalid length.
0
Attacker Value
Unknown
CVE-2024-49834
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while power-up or power-down sequence of the camera sensor.
0
Attacker Value
Unknown
CVE-2024-49833
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption can occur in the camera when an invalid CID is used.
0
Attacker Value
Unknown
CVE-2024-49832
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
0
Attacker Value
Unknown
CVE-2024-45584
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
0
Attacker Value
Unknown
CVE-2024-45582
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while validating number of devices in Camera kernel .
0