CVE-2024-34722
- EPSS 0.15%
- Veröffentlicht 09.07.2024 21:15:14
- Zuletzt bearbeitet 21.01.2025 23:15:13
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User ...
CVE-2024-34723
- EPSS 0.03%
- Veröffentlicht 09.07.2024 21:15:14
- Zuletzt bearbeitet 17.12.2024 18:15:21
In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges ...
- EPSS 0.02%
- Veröffentlicht 09.07.2024 21:15:14
- Zuletzt bearbeitet 17.12.2024 18:14:30
In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for...
- EPSS 0.02%
- Veröffentlicht 09.07.2024 21:15:14
- Zuletzt bearbeitet 17.12.2024 18:14:22
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is no...
CVE-2024-34726
- EPSS 0.03%
- Veröffentlicht 09.07.2024 21:15:14
- Zuletzt bearbeitet 17.12.2024 18:14:01
In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not ne...
CVE-2024-31314
- EPSS 0.07%
- Veröffentlicht 09.07.2024 21:15:13
- Zuletzt bearbeitet 17.12.2024 17:28:52
In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-31315
- EPSS 0.03%
- Veröffentlicht 09.07.2024 21:15:13
- Zuletzt bearbeitet 19.03.2025 18:15:20
In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications settings due to improper input validation. This could lead to local escalation of privilege with no addit...
CVE-2024-31316
- EPSS 0.05%
- Veröffentlicht 09.07.2024 21:15:13
- Zuletzt bearbeitet 17.12.2024 17:21:22
In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVE-2024-31317
- EPSS 7.03%
- Veröffentlicht 09.07.2024 21:15:13
- Zuletzt bearbeitet 17.12.2024 17:19:27
In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed....
CVE-2024-31318
- EPSS 0.05%
- Veröffentlicht 09.07.2024 21:15:13
- Zuletzt bearbeitet 17.12.2024 17:16:10
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User...