CVE-2023-21141 |
Description: In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262244249
EPSS Score: 0.04%
December 18th, 2024 (6 months ago)
|
CVE-2023-21139 |
Description: In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-271845008
EPSS Score: 0.04%
December 18th, 2024 (6 months ago)
|
CVE-2023-21138 |
Description: In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-273260090
EPSS Score: 0.04%
December 18th, 2024 (6 months ago)
|
CVE-2024-5660 |
Description: Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.
EPSS Score: 0.04%
December 17th, 2024 (6 months ago)
|
CVE-2024-56112 |
Description: CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
EPSS Score: 0.04%
December 17th, 2024 (6 months ago)
|
CVE-2024-56087 |
Description: An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
EPSS Score: 0.04%
December 17th, 2024 (6 months ago)
|
CVE-2024-56086 |
Description: An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.
EPSS Score: 0.04%
December 17th, 2024 (6 months ago)
|
CVE-2024-56085 |
Description: An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
EPSS Score: 0.04%
December 17th, 2024 (6 months ago)
|
CVE-2024-56084 |
Description: An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.
EPSS Score: 0.04%
December 17th, 2024 (6 months ago)
|
CVE-2024-56083 |
Description: Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin session to social media, or publicly streams their Devin session.
EPSS Score: 0.05%
December 17th, 2024 (6 months ago)
|