NA - CVE-2024-52769 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
NA - CVE-2024-52770 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
NA - CVE-2024-52796 - Password Pusher, an open source application to...
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be...
NA - CVE-2018-9470 - In bff_Scanner_addOutPos of Scanner.c, there is...
In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no...
NA - CVE-2018-9471 - In the deserialization constructor of...
In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no...
NA - CVE-2018-9472 - In xmlMemStrdupLoc of xmlmemory.c, there is a...
In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional...
NA - CVE-2018-9474 - In writeToParcel of MediaPlayer.java, there is...
In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no...
NA - CVE-2018-9475 - In HeadsetInterface::ClccResponse of...
In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation of privilege via Bluetooth, if the...
NA - CVE-2018-9477 - In the development options section of the...
In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no...