CVE-2024-34719
- EPSS 0.01%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:41:51
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-34729
- EPSS 0.05%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:39:04
In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for ex...
CVE-2024-34747
- EPSS 0.02%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:37:38
In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not n...
CVE-2024-40660
- EPSS 0.02%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:36:04
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVE-2024-40661
- EPSS 0.01%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:32:42
In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. U...
CVE-2024-40671
- EPSS 0.04%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:30:29
In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVE-2024-43080
- EPSS 0.05%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 19:10:30
In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for e...
CVE-2024-43081
- EPSS 0.02%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 18:56:04
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVE-2024-43082
- EPSS 0.01%
- Veröffentlicht 13.11.2024 18:15:20
- Zuletzt bearbeitet 17.12.2024 20:03:15
In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVE-2023-35659
- EPSS 0.02%
- Veröffentlicht 13.11.2024 18:15:19
- Zuletzt bearbeitet 20.11.2024 17:35:20
In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interac...