6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34677
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

CVE-2024-34633
Samsung Notes General
4.0
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVE-2024-34658
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

CVE-2024-20835
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.

CVE-2024-0321
gpac/gpac General
4.0
MEDIUM
EPSS
0.1%
2024 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2024-34636
Samsung Email General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

CVE-2024-20857
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

CVE-2024-57822
Raptor RDF Syntax Library General
4.0
MEDIUM
EPSS
0.0%
2024 CWE-125 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

CVE-2024-36062
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.

CVE-2024-33883
Software Genérico Web
4.0
MEDIUM
EPSS
1.3%
2024 1 PoC

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

CVE-2024-45989
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server.

CVE-2024-6790
Bifrost GPU Kernel Driver General
4.0
MEDIUM
EPSS
0.1%
2024 CWE-835 1 PoC

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a non-privileged user process to make valid GPU memory processing operations, including via WebGL or WebGPU, to cause the whole system to become unresponsive.This issue affects Bifrost GPU Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0; Valhall GPU Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0; Arm 5th Gen GPU Architecture Kernel Driver: r44p1,

CVE-2024-34647
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

CVE-2024-21100
Commerce Platform Web Database
4.0
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. While the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Sco

CVE-2024-20879
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2024-34652
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

CVE-2024-20804
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

CVE-2024-34599
Tips General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.

CVE-2024-4755
Google CSE Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-36795
Software Genérico General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.