| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21427 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2024-21426 | Hig | 0.51 | 7.8 | 0.04 | Mar 12, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-21421 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Azure SDK Spoofing Vulnerability | ||
| CVE-2024-21419 | Hig | 0.49 | 7.6 | 0.01 | Mar 12, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2024-21418 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability | ||
| CVE-2024-21411 | Hig | 0.57 | 8.8 | 0.03 | Mar 12, 2024 | Skype for Consumer Remote Code Execution Vulnerability | ||
| CVE-2024-21407 | Hig | 0.54 | 8.1 | 0.16 | Mar 12, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2024-21392 | Hig | 0.42 | 7.5 | 0.03 | Mar 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2024-21390 | Hig | 0.46 | 7.1 | 0.01 | Mar 12, 2024 | Microsoft Authenticator Elevation of Privilege Vulnerability | ||
| CVE-2024-21330 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | ||
| CVE-2024-27758 | Hig | 0.48 | 8.4 | 0.01 | Mar 12, 2024 | In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution. | ||
| CVE-2024-1529 | Hig | 0.48 | 7.4 | 0.00 | Mar 12, 2024 | Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially… | ||
| CVE-2024-1528 | Hig | 0.48 | 7.4 | 0.00 | Mar 12, 2024 | CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted… | ||
| CVE-2024-1302 | Hig | 0.47 | 7.3 | 0.00 | Mar 12, 2024 | Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials. | ||
| CVE-2024-23112 | Hig | 0.52 | 8.0 | 0.01 | Mar 12, 2024 | An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may… | ||
| CVE-2024-1618 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. An attacker with local user privileges could exploit this vulnerability to replace the… | ||
| CVE-2024-1226 | — | Hig | 0.49 | 7.5 | 0.00 | Mar 12, 2024 | The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker… | |
| CVE-2023-46717 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts. | ||
| CVE-2023-42790 | Hig | 0.53 | 8.1 | 0.01 | Mar 12, 2024 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through… | ||
| CVE-2023-36554 | Hig | 0.53 | 8.1 | 0.01 | Mar 12, 2024 | A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | ||
| CVE-2024-27907 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted Catia MODEL file. This could allow an attacker to execute code in… | ||
| CVE-2024-22045 | Hig | 0.49 | 7.6 | 0.00 | Mar 12, 2024 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This… | ||
| CVE-2024-22044 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create… | ||
| CVE-2024-22041 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200… | ||
| CVE-2024-22040 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200… | ||
| CVE-2024-26288 | Hig | 0.57 | 8.7 | 0.00 | Mar 12, 2024 | An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected. | ||
| CVE-2024-26004 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality. | ||
| CVE-2024-26003 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. | ||
| CVE-2024-26002 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files. | ||
| CVE-2024-26001 | Hig | 0.48 | 7.4 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization. | ||
| CVE-2024-25999 | Hig | 0.55 | 8.4 | 0.00 | Mar 12, 2024 | An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. | ||
| CVE-2024-25998 | Hig | 0.48 | 7.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. | ||
| CVE-2024-27121 | Hig | 0.47 | 7.2 | 0.01 | Mar 12, 2024 | Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote… | ||
| CVE-2024-25325 | Hig | 0.46 | 7.1 | 0.00 | Mar 12, 2024 | SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php. | ||
| CVE-2024-21805 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's… | ||
| CVE-2024-28199 | Hig | 0.39 | 7.1 | 0.01 | Mar 11, 2024 | phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent… | ||
| CVE-2022-46070 | Hig | 0.49 | 7.5 | 0.00 | Mar 11, 2024 | GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path. | ||
| CVE-2024-28197 | Hig | 0.42 | 7.5 | 0.00 | Mar 11, 2024 | Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL instance. An attacker could take… | ||
| CVE-2024-28187 | Hig | 0.00 | 7.2 | 0.02 | Mar 11, 2024 | SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 are vulnerable to an OS Command Injection vulnerability within the file upload feature when accessed by an administrator. The vulnerability… | ||
| CVE-2024-27236 | Hig | 0.55 | 8.4 | 0.00 | Mar 11, 2024 | In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27233 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2024 | In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27229 | Hig | 0.49 | 7.5 | 0.00 | Mar 11, 2024 | In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27226 | Hig | 0.55 | 8.4 | 0.00 | Mar 11, 2024 | In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27224 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2024 | In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27222 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2024 | In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2024-27221 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2024 | In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27220 | Hig | 0.55 | 8.4 | 0.00 | Mar 11, 2024 | In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27219 | Hig | 0.55 | 8.4 | 0.00 | Mar 11, 2024 | In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27213 | Hig | 0.55 | 8.4 | 0.00 | Mar 11, 2024 | In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-27212 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2024 | In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
- risk 0.49cvss 7.5epss 0.02
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.04
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Azure SDK Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.51cvss 7.8epss 0.01
Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Skype for Consumer Remote Code Execution Vulnerability
- risk 0.54cvss 8.1epss 0.16
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.42cvss 7.5epss 0.03
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Authenticator Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
- risk 0.48cvss 8.4epss 0.01
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
- risk 0.48cvss 7.4epss 0.00
Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially…
- risk 0.48cvss 7.4epss 0.00
CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted…
- risk 0.47cvss 7.3epss 0.00
Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.
- risk 0.52cvss 8.0epss 0.01
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may…
- risk 0.51cvss 7.8epss 0.00
A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. An attacker with local user privileges could exploit this vulnerability to replace the…
- risk 0.49cvss 7.5epss 0.00
The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker…
- risk 0.49cvss 7.5epss 0.01
An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.
- risk 0.53cvss 8.1epss 0.01
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through…
- risk 0.53cvss 8.1epss 0.01
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
- risk 0.51cvss 7.8epss 0.00
A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted Catia MODEL file. This could allow an attacker to execute code in…
- risk 0.49cvss 7.6epss 0.00
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200…
- risk 0.57cvss 8.7epss 0.00
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.
- risk 0.51cvss 7.8epss 0.00
An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
- risk 0.48cvss 7.4epss 0.01
An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
- risk 0.48cvss 7.3epss 0.01
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
- risk 0.47cvss 7.2epss 0.01
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote…
- risk 0.46cvss 7.1epss 0.00
SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.
- risk 0.51cvss 7.8epss 0.00
Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's…
- risk 0.39cvss 7.1epss 0.01
phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent…
- risk 0.49cvss 7.5epss 0.00
GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.
- risk 0.42cvss 7.5epss 0.00
Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL instance. An attacker could take…
- risk 0.00cvss 7.2epss 0.02
SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 are vulnerable to an OS Command Injection vulnerability within the file upload feature when accessed by an administrator. The vulnerability…
- risk 0.55cvss 8.4epss 0.00
In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.49cvss 7.5epss 0.00
In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.55cvss 8.4epss 0.00
In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.51cvss 7.8epss 0.00
In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.55cvss 8.4epss 0.00
In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.55cvss 8.4epss 0.00
In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.55cvss 8.4epss 0.00
In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.