|
312201
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
|
NVD-CWE-noinfo
|
CVE-2024-34647
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312202
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34652
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312203
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34651
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312204
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34650
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312205
|
2.4 |
LOW
Physics
|
samsung
|
android
|
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
|
NVD-CWE-Other
|
CVE-2024-34649
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312206
|
4.3 |
MEDIUM
Network
|
samsung
|
assistant
|
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerab…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-34661
|
2024-09-6 02:57 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312207
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent possible UAF in ip6_xmit()
If skb_expand_head() returns NULL, skb has been freed
and the associated dst/idev could …
|
CWE-416
Use After Free
|
CVE-2024-44985
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312208
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
workqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask()
UBSAN reports the following 'subtraction overflow' error wh…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-44981
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312209
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register()
bcm_sf2_mdio_register() calls of_phy_find_device() and t…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-44971
|
2024-09-6 02:54 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312210
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv6: prevent UAF in ip6_send_skb()
syzbot reported an UAF in ip6_send_skb() [1]
After ip6_local_out() has returned, we no longe…
|
CWE-416
Use After Free
|
CVE-2024-44987
|
2024-09-6 02:53 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|