|
313171
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvme: apple: fix device reference counting
Drivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.
Split the alloca…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-43913
|
2024-09-6 03:12 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313172
|
7.1 |
HIGH
Local
|
samsung
|
android
|
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-34638
|
2024-09-6 03:05 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313173
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on…
|
NVD-CWE-Other
|
CVE-2024-34637
|
2024-09-6 03:05 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313174
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
|
CWE-22
Path Traversal
|
CVE-2024-34653
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313175
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-34648
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313176
|
3.3 |
LOW
Local
|
samsung
|
android
|
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
|
NVD-CWE-Other
|
CVE-2024-34640
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313177
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-34639
|
2024-09-6 03:04 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313178
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulner…
|
NVD-CWE-Other
|
CVE-2024-34644
|
2024-09-6 03:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313179
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vu…
|
NVD-CWE-Other
|
CVE-2024-34643
|
2024-09-6 03:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313180
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34642
|
2024-09-6 03:03 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|