Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-10254
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
0
Attacker Value
Unknown
CVE-2024-10253
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
0
Attacker Value
Unknown
CVE-2024-1610
Disclosure Date: December 18, 2024 (last updated December 18, 2024)
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-4130
Disclosure Date: October 11, 2024 (last updated October 18, 2024)
A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2024-39886
Disclosure Date: July 10, 2024 (last updated July 10, 2024)
TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.
0
Attacker Value
Unknown
CVE-2023-6450
Disclosure Date: January 19, 2024 (last updated January 27, 2024)
An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2022-3611
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications.
0
Attacker Value
Unknown
CVE-2020-14121
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.
0
Attacker Value
Unknown
CVE-2020-14118
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps.
0