|
312621
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34651
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312622
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34650
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312623
|
2.4 |
LOW
Physics
|
samsung
|
android
|
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
|
NVD-CWE-Other
|
CVE-2024-34649
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312624
|
4.3 |
MEDIUM
Network
|
samsung
|
assistant
|
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerab…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-34661
|
2024-09-6 02:57 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312625
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent possible UAF in ip6_xmit()
If skb_expand_head() returns NULL, skb has been freed
and the associated dst/idev could …
|
CWE-416
Use After Free
|
CVE-2024-44985
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312626
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
workqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask()
UBSAN reports the following 'subtraction overflow' error wh…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-44981
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312627
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()
bcm_sf2_mdio_register() calls of_phy_find_device() and t…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-44971
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312628
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent UAF in ip6_send_skb()
syzbot reported an UAF in ip6_send_skb() [1]
After ip6_local_out() has returned, we no longe…
|
CWE-416
Use After Free
|
CVE-2024-44987
|
2024-09-6 02:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312629
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
power: supply: rt5033: Bring back i2c_set_clientdata
Commit 3a93da231c12 ("power: supply: rt5033: Use devm_power_supply_register(…
|
NVD-CWE-noinfo
|
CVE-2024-44936
|
2024-09-6 02:53 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312630
|
7.8 |
HIGH
Local
|
overwolf
|
overwolf
|
A local privilege escalation is caused by Overwolf
loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an attacker with unpr…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-7834
|
2024-09-6 02:52 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|