3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-49403
Samsung Voice Recorder General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.

CVE-2024-20827
Gallery General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

CVE-2024-37601
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.

CVE-2024-37603
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.

CVE-2024-35106
Software Genérico General
4.6
MEDIUM
EPSS
0.3%
2024 1 PoC

NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.

CVE-2024-3843
Chrome General
4.6
MEDIUM
EPSS
0.7%
2024 1 PoC

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-31799
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2024 1 PoC

Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.

CVE-2024-49407
Samsung Flow General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.

CVE-2024-12247
Mattermost General
4.6
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

CVE-2024-34642
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

CVE-2024-20802
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users&#39; notification in a multi-user environment.

CVE-2024-22854
Software Genérico General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form.

CVE-2024-34653
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

CVE-2024-20839
Samsung Voice Recorder General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen.

CVE-2024-34674
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

CVE-2024-45833
Mattermost General
4.5
MEDIUM
EPSS
0.2%
2024 CWE-693 1 PoC

Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..

CVE-2024-21530
cocoon General
4.5
MEDIUM
EPSS
0.0%
2024 CWE-323 1 PoC

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with the same cocoon object. **Note:** The issue does NOT affect objects created with Cocoon::new which utilizes ThreadRng.

CVE-2024-0322
gpac/gpac General
4.4
MEDIUM
EPSS
0.2%
2024 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2024-27362
Software Genérico General
4.4
MEDIUM
EPSS
0.3%
2024 2 PoCs

A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not properly check the length of the data, which can lead to a Information disclosure.

CVE-2024-27367
Software Genérico General
4.4
MEDIUM
EPSS
0.0%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_ind(), there is no input validation check on a length coming from userspace, which can lead to integer overflow and a potential heap over-read.