CVE-2024-20899
- EPSS 0.07%
- Published 02.07.2024 10:15:05
- Last modified 21.11.2024 08:53:23
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
CVE-2024-20900
- EPSS 0.1%
- Published 02.07.2024 10:15:05
- Last modified 21.11.2024 08:53:23
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
CVE-2024-20901
- EPSS 0.06%
- Published 02.07.2024 10:15:05
- Last modified 21.11.2024 08:53:23
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2024-20891
- EPSS 0.03%
- Published 02.07.2024 10:15:04
- Last modified 21.11.2024 08:53:22
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
CVE-2024-20892
- EPSS 0.02%
- Published 02.07.2024 10:15:04
- Last modified 21.11.2024 08:53:22
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.
CVE-2024-20893
- EPSS 0.03%
- Published 02.07.2024 10:15:04
- Last modified 21.11.2024 08:53:22
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.
CVE-2024-20894
- EPSS 0.02%
- Published 02.07.2024 10:15:04
- Last modified 21.11.2024 08:53:22
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
CVE-2024-20895
- EPSS 0.01%
- Published 02.07.2024 10:15:04
- Last modified 21.11.2024 08:53:22
Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.
CVE-2024-20896
- EPSS 0.03%
- Published 02.07.2024 10:15:04
- Last modified 21.11.2024 08:53:23
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
CVE-2024-20888
- EPSS 0.03%
- Published 02.07.2024 10:15:03
- Last modified 21.11.2024 08:53:21
Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.