NA - CVE-2024-43086 - In validateAccountsInternal of...
In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could lead to local information...
NA - CVE-2024-43087 - In getInstalledAccessibilityPreferences of...
In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in...
NA - CVE-2024-43088 - In multiple functions in AppInfoBase.java,...
In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead...
NA - CVE-2024-43089 - In updateInternal of MediaProvider.java , there...
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no...
NA - CVE-2024-43090 - In multiple locations, there is a possible...
In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User...
NA - CVE-2024-43091 - In filterMask of SkEmbossMaskFilter.cpp, there...
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed....
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization....
NA - CVE-2024-49379 - Umbrel is a home server OS for self-hosting....
Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can...
NA - CVE-2023-38920 - Cross Site Scripting vulnerability in Cyber...
Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.
NA - CVE-2024-40443 - SQL Injection vulnerability in Simple...
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php