CVE-2018-9447
- EPSS 0.01%
- Published 17.01.2025 23:15:12
- Last modified 10.07.2025 20:42:54
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction...
CVE-2018-9375
- EPSS 0.03%
- Published 17.01.2025 23:15:11
- Last modified 03.07.2025 15:00:59
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVE-2018-9379
- EPSS 0.02%
- Published 17.01.2025 23:15:11
- Last modified 10.07.2025 20:43:43
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction i...
CVE-2018-9382
- EPSS 0.02%
- Published 17.01.2025 23:15:11
- Last modified 10.07.2025 20:43:33
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges need...
CVE-2017-13322
- EPSS 0.04%
- Published 17.01.2025 23:15:10
- Last modified 13.03.2025 14:15:19
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. Use...
CVE-2023-35685
- EPSS 0.03%
- Published 08.01.2025 18:15:15
- Last modified 31.01.2025 18:15:34
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not...
CVE-2024-20148
- EPSS 0.08%
- Published 06.01.2025 04:15:07
- Last modified 22.04.2025 13:50:16
In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Pa...
CVE-2024-20152
- EPSS 0%
- Published 06.01.2025 04:15:07
- Last modified 21.04.2025 17:12:10
In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation...
CVE-2024-20105
- EPSS 0.01%
- Published 06.01.2025 04:15:06
- Last modified 22.04.2025 13:49:48
In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID:...
CVE-2024-20140
- EPSS 0.01%
- Published 06.01.2025 04:15:06
- Last modified 22.04.2025 13:49:53
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch I...