Show filters
464 Total Results
Displaying 31-40 of 464
Sort by:
Attacker Value
Unknown

CVE-2024-12603

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.
0
Attacker Value
Unknown

CVE-2024-10576

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.  After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
0
Attacker Value
Unknown

CVE-2024-11206

Disclosure Date: November 14, 2024 (last updated November 14, 2024)
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
0
Attacker Value
Unknown

CVE-2024-33617

Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Insufficient control flow management in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.
0
Attacker Value
Unknown

CVE-2024-31074

Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.
0
Attacker Value
Unknown

CVE-2024-28885

Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.
0
Attacker Value
Unknown

CVE-2024-4741

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers function are affected by this issue. Applications that do not call this function are not vulnerable. Our investigations indicate that this function is rarely used by applications. The SSL_free_buffers function is used to free the internal OpenSSL buffer used when processing an incoming record from the network. The call is only expected to succeed if the buffer is not currently in use. However, two scenarios have been identified where the buffer is freed even when still in use. The first scenario occurs where a record header has been received from the network and processed by OpenSSL, but the full record body has not yet arriv…
0
Attacker Value
Unknown

CVE-2024-9143

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound memory writes can lead to an application crash or even a possibility of a remote code execution, however, in all the protocols involving Elliptic Curve Cryptography that we're aware of, either only "named curves" are supported, or, if explicit curve parameters are supported, they specify an X9.62 encoding of binary (GF(2^m)) curves that can't represent problematic input values. Thus the likelihood of existence of a vulnerable application is low. In particular, the X9.62 encoding is used for ECC keys in X.509 certificates, so problematic inputs cannot occur in the context of processing X.509 certificates. Any problematic use-cases would have to be using an "exotic" curve encoding. The affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(), and various supporting BN…
0
Attacker Value
Unknown

CVE-2024-10018

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.
0
Attacker Value
Unknown

CVE-2024-9021

Disclosure Date: October 08, 2024 (last updated October 08, 2024)
In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor
0