NA - CVE-2024-0035 - In onNullBinding of TileLifecycleManager.java,...
In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with...
NA - CVE-2024-0036 - In startNextMatchingActivity of...
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This...
NA - CVE-2024-0037 - In applyCustomDescription of SaveUi.java, there...
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check. This could lead to local information disclosure...
NA - CVE-2024-0038 - In injectInputEventToInputFilter of...
In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of...
NA - CVE-2024-0040 - In setParameter of MtpPacket.cpp, there is a...
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges...
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to...
NA - CVE-2024-25413 - A XSLT Server Side injection vulnerability in...
A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.
NA - CVE-2024-25414 - An arbitrary file upload vulnerability in...
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.
NA - CVE-2024-25415 - A remote code execution (RCE) vulnerability in...
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file...
NA - CVE-2023-6451 - Publicly known cryptographic machine key in...
Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's...