Show filters
2,035 Total Results
Displaying 41-50 of 2,035
Sort by:
Attacker Value
Unknown
CVE-2024-43083
Disclosure Date: November 13, 2024 (last updated December 18, 2024)
In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-43082
Disclosure Date: November 13, 2024 (last updated December 18, 2024)
In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-43081
Disclosure Date: November 13, 2024 (last updated December 18, 2024)
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-43080
Disclosure Date: November 13, 2024 (last updated December 18, 2024)
In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-40661
Disclosure Date: November 13, 2024 (last updated December 18, 2024)
In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-34719
Disclosure Date: November 13, 2024 (last updated December 18, 2024)
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-34680
Disclosure Date: November 06, 2024 (last updated November 13, 2024)
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
0
Attacker Value
Unknown
CVE-2024-34678
Disclosure Date: November 06, 2024 (last updated November 13, 2024)
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.
0
Attacker Value
Unknown
CVE-2024-34677
Disclosure Date: November 06, 2024 (last updated November 13, 2024)
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
0
Attacker Value
Unknown
CVE-2024-34676
Disclosure Date: November 06, 2024 (last updated November 13, 2024)
Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
0