Show filters
1,135 Total Results
Displaying 31-40 of 1,135
Sort by:
Attacker Value
Unknown

CVE-2025-24803

Disclosure Date: February 05, 2025 (last updated February 06, 2025)
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.). However, an attacker can manually modify this value in the `Info.plist` file and add special characters to the `<key>CFBundleIdentifier</key>` value. The `dynamic_analysis.html` file does not sanitize the received bundle value from Corellium and as a result, it is possible to break the HTML context and achieve Stored XSS. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown

CVE-2025-20906

Disclosure Date: February 04, 2025 (last updated February 04, 2025)
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.
0
Attacker Value
Unknown

CVE-2024-49843

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.
Attacker Value
Unknown

CVE-2024-49839

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption during management frame processing due to mismatch in T2LM info element.
Attacker Value
Unknown

CVE-2024-49838

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Information disclosure while parsing the OCI IE with invalid length.
Attacker Value
Unknown

CVE-2024-49834

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while power-up or power-down sequence of the camera sensor.
Attacker Value
Unknown

CVE-2024-49833

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption can occur in the camera when an invalid CID is used.
Attacker Value
Unknown

CVE-2024-49832

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption in Camera due to unusually high number of nodes passed to AXI port.
Attacker Value
Unknown

CVE-2024-45584

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
Attacker Value
Unknown

CVE-2024-45582

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while validating number of devices in Camera kernel .