CVE-2024-0039
- EPSS 26.25%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 13.03.2025 19:15:40
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVE-2024-0044
- EPSS 7.84%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 28.01.2025 20:15:30
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...
CVE-2024-0045
- EPSS 0.1%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 17.12.2024 15:41:13
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not n...
CVE-2024-0046
- EPSS 0%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 16.12.2024 19:50:16
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVE-2024-0047
- EPSS 0.04%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 27.03.2025 16:15:20
In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privile...
CVE-2024-0048
- EPSS 0.02%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 16.12.2024 19:47:07
In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local escalation of privilege with no additional execution privileges needed....
CVE-2024-0049
- EPSS 0.04%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 16.12.2024 19:45:40
In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-0050
- EPSS 0.02%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 16.12.2024 19:38:57
In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could lead to a local non-security issue with no additional execution privileges needed. User interaction is not needed ...
CVE-2024-0051
- EPSS 0.08%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 16.12.2024 19:32:07
In onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVE-2024-0052
- EPSS 0.02%
- Veröffentlicht 11.03.2024 17:15:45
- Zuletzt bearbeitet 13.03.2025 19:15:41
In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...