|
250411
|
7.8 |
HIGH
Local
|
google
|
android
|
In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47012
|
2024-10-28 22:58 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250412
|
7.5 |
HIGH
Network
|
google
|
android
|
In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution pr…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-47021
|
2024-10-28 22:57 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250413
|
5.5 |
MEDIUM
Local
|
google
|
android
|
There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction…
|
CWE-863
Incorrect Authorization
|
CVE-2024-44099
|
2024-10-28 22:56 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250414
|
7.5 |
HIGH
Network
|
google
|
android
|
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.
|
NVD-CWE-noinfo
|
CVE-2024-47020
|
2024-10-28 22:55 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250415
|
7.5 |
HIGH
Network
|
google
|
android
|
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
|
NVD-CWE-noinfo
|
CVE-2024-44100
|
2024-10-28 22:50 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250416
|
7.5 |
HIGH
Network
|
google
|
android
|
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.
|
NVD-CWE-noinfo
|
CVE-2024-47022
|
2024-10-28 22:47 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250417
|
8.1 |
HIGH
Network
|
google
|
android
|
there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is no…
|
NVD-CWE-noinfo
|
CVE-2024-47023
|
2024-10-28 22:33 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250418
|
- |
|
-
|
-
|
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.
For this to impact an application, all of the following mus…
|
-
|
CVE-2024-38821
|
2024-10-28 16:15 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250419
|
7.2 |
HIGH
Network
|
-
|
-
|
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7…
|
CWE-94
Code Injection
|
CVE-2024-9162
|
2024-10-28 15:15 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250420
|
- |
|
-
|
-
|
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file m…
|
-
|
CVE-2024-50307
|
2024-10-28 14:15 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|