CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-39900

    Last Modified: 21 Nov 2024

    OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.

    Published: 9 Jul 2024
    4.2
    Medium

    CVE-2024-39901

    Last Modified: 21 Nov 2024

    OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-34726

    Last Modified: 17 Dec 2024

    In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7
    High

    CVE-2024-34725

    Last Modified: 17 Dec 2024

    In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7
    High

    CVE-2024-34724

    Last Modified: 17 Dec 2024

    In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-34723

    Last Modified: 17 Dec 2024

    In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-34722

    Last Modified: 21 Jan 2025

    In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-34721

    Last Modified: 17 Dec 2024

    In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-34720

    Last Modified: 17 Dec 2024

    In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible method to perform arbitrary code execution in any app zygote processes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31339

    Last Modified: 17 Dec 2024

    In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31335

    Last Modified: 17 Dec 2024

    In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31334

    Last Modified: 17 Dec 2024

    In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31332

    Last Modified: 13 Mar 2025

    In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.3
    High

    CVE-2024-31331

    Last Modified: 14 Mar 2025

    In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31320

    Last Modified: 17 Dec 2024

    In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7
    High

    CVE-2024-31327

    Last Modified: 14 Mar 2025

    In multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31326

    Last Modified: 17 Dec 2024

    In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31325

    Last Modified: 17 Dec 2024

    In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.3
    High

    CVE-2024-31324

    Last Modified: 15 Mar 2025

    In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode first and then rotating it to landscape mode. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31323

    Last Modified: 17 Dec 2024

    In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31322

    Last Modified: 17 Dec 2024

    In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessibility Service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31319

    Last Modified: 17 Dec 2024

    In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31318

    Last Modified: 17 Dec 2024

    In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31317

    Last Modified: 17 Dec 2024

    In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31316

    Last Modified: 13 Mar 2025

    In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31315

    Last Modified: 19 Mar 2025

    In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-31314

    Last Modified: 17 Dec 2024

    In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31313

    Last Modified: 17 Dec 2024

    In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-31312

    Last Modified: 17 Dec 2024

    In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31311

    Last Modified: 17 Dec 2024

    In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-31310

    Last Modified: 27 Mar 2025

    In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-23711

    Last Modified: 17 Dec 2024

    In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-23698

    Last Modified: 17 Dec 2024

    In RGXFWChangeOSidPriority of rgxfwutils.c, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-23697

    Last Modified: 17 Dec 2024

    In RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-23696

    Last Modified: 17 Dec 2024

    In RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-23695

    Last Modified: 17 Dec 2024

    In CacheOpPMRExec of cache_km.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2023-21114

    Last Modified: 17 Dec 2024

    In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2023-21113

    Last Modified: 13 Mar 2025

    In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-34140

    Last Modified: 21 Nov 2024

    Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-34139

    Last Modified: 21 Nov 2024

    Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-20781

    Last Modified: 21 Nov 2024

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-20785

    Last Modified: 21 Nov 2024

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-20783

    Last Modified: 21 Nov 2024

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-20782

    Last Modified: 21 Nov 2024

    InDesign Desktop versions ID19.3, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jul 2024
    —
    Unknown

    CVE-2024-6630

    Last Modified: 10 Jul 2024

    **REJECT** This CVE ID was issued in error and is a duplicate. Please use CVE-2024-6500 instead.

    Published: 9 Jul 2024
    7
    High

    CVE-2024-34123

    Last Modified: 3 Dec 2024

    Premiere Pro versions 23.6.5, 24.4.1 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead of the legitimate file. This could occur when the application uses a search path to locate executables or libraries. Exploitation of this issue requires user interaction, attack complexity is high.

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-39899

    Last Modified: 15 Apr 2026

    PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance without authentication and/or exposing the authentication token to the public, allowing anyone to shorten any URL. With the proxy mechanism, anyone can shorten any URL pointing to the configured PrivateBin instance. The vulnerability allowed other URLs to be shortened, as long as they contain the PrivateBin instance, defeating the limit imposed by the proxy. This vulnerability is fixed in 1.7.4.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-39897

    Last Modified: 23 Apr 2025

    zot is an OCI image registry. Prior to 2.1.0, the cache driver `GetBlob()` allows read access to any blob without access control check. If a Zot `accessControl` policy allows users read access to some repositories but restricts read access to other repositories and `dedupe` is enabled (it is enabled by default), then an attacker who knows the name of an image and the digest of a blob (that they do not have read access to), they may maliciously read it via a second repository they do have read access to. This attack is possible because [`ImageStore.CheckBlob()` calls `checkCacheBlob()`](https://github.com/project-zot/zot/blob/v2.1.0-rc2/pkg/storage/imagestore/imagestore.go#L1158-L1159) to find the blob a global cache by searching for the digest. If it is found, it is copied to the user requested repository with `copyBlob()`. The attack may be mitigated by configuring "dedupe": false in the "storage" settings. The vulnerability is fixed in 2.1.0.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-27183

    Last Modified: 18 Mar 2025

    XSS vulnerability in DJ-HelpfulArticles component for Joomla.

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-39698

    Last Modified: 21 Nov 2024

    electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` implements the signature validation routine for Electron applications on Windows. Because of the surrounding shell, a first pass by `cmd.exe` expands any environment variable found in command-line above. This creates a situation where `verifySignature()` can be tricked into validating the certificate of a different file than the one that was just downloaded. If the step is successful, the malicious update will be executed even if its signature is invalid. This attack assumes a compromised update manifest (server compromise, Man-in-the-Middle attack if fetched over HTTP, Cross-Site Scripting to point the application to a malicious updater server, etc.). The patch is available starting from 6.3.0-alpha.6.

    Published: 9 Jul 2024