Show filters
7,909 Total Results
Displaying 91-100 of 7,909
Sort by:
Attacker Value
Unknown

CVE-2018-9447

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9434

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9384

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9383

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9382

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9379

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9375

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2017-13322

Disclosure Date: January 17, 2025 (last updated January 24, 2025)
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-35685

Disclosure Date: January 08, 2025 (last updated February 27, 2025)
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2024-12402

Disclosure Date: January 07, 2025 (last updated February 27, 2025)
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.4. This is due to the plugin not properly validating a user's identity prior to updating their password through the update_user_profile() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.