CVE-2024-24938
Last Modified: 27 Aug 2025In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
CVE-2024-24937
Last Modified: 21 Nov 2024In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
CVE-2024-24936
Last Modified: 21 Nov 2024In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
CVE-2023-32479
Last Modified: 21 Nov 2024Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.
CVE-2023-32454
Last Modified: 21 Nov 2024DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service
CVE-2023-32474
Last Modified: 21 Nov 2024Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion
CVE-2024-1271
Last Modified: 19 Nov 2024This CVE was previously published at https://bugzilla.redhat.com/show_bug.cgi?id=2262978 but later rejected for the following reason: The flaw requires an attacker to have superuser credentials which is a condition that already permits all impacts, hence not constituing a security vulnerability.
CVE-2023-32451
Last Modified: 21 Nov 2024Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation
CVE-2023-28063
Last Modified: 21 Nov 2024Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
CVE-2023-28049
Last Modified: 21 Nov 2024Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.
CVE-2023-25543
Last Modified: 21 Nov 2024Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system.
CVE-2023-43536
Last Modified: 11 Aug 2025Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43535
Last Modified: 13 Jun 2025Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
CVE-2023-43534
Last Modified: 11 Aug 2025Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
CVE-2023-43533
Last Modified: 11 Aug 2025Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2023-43532
Last Modified: 17 Jun 2025Memory corruption while reading ACPI config through the user mode app.
CVE-2023-43523
Last Modified: 17 Jun 2025Transient DOS while processing 11AZ RTT management action frame received through OTA.
CVE-2023-43522
Last Modified: 11 Aug 2025Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
CVE-2023-43520
Last Modified: 11 Aug 2025Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
CVE-2023-43519
Last Modified: 11 Aug 2025Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.
CVE-2023-43518
Last Modified: 11 Aug 2025Memory corruption in video while parsing invalid mp2 clip.
CVE-2023-43517
Last Modified: 15 May 2025Memory corruption in Automotive Multimedia due to improper access control in HAB.
CVE-2023-43516
Last Modified: 15 May 2025Memory corruption when malformed message payload is received from firmware.
CVE-2023-43513
Last Modified: 11 Aug 2025Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
CVE-2023-33077
Last Modified: 11 Aug 2025Memory corruption in HLOS while converting from authorization token to HIDL vector.
CVE-2023-33076
Last Modified: 17 Jun 2025Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
CVE-2023-33072
Last Modified: 11 Aug 2025Memory corruption in Core while processing control functions.
CVE-2023-33069
Last Modified: 11 Aug 2025Memory corruption in Audio while processing the calibration data returned from ACDB loader.
CVE-2023-33068
Last Modified: 11 Aug 2025Memory corruption in Audio while processing IIR config data from AFE calibration block.
CVE-2023-33067
Last Modified: 11 Aug 2025Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
CVE-2023-33065
Last Modified: 11 Aug 2025Information disclosure in Audio while accessing AVCS services from ADSP payload.
CVE-2023-33064
Last Modified: 11 Aug 2025Transient DOS in Audio when invoking callback function of ASM driver.
CVE-2023-33060
Last Modified: 21 Nov 2024Transient DOS in Core when DDR memory check is called while DDR is not initialized.
CVE-2023-33058
Last Modified: 21 Nov 2024Information disclosure in Modem while processing SIB5.
CVE-2023-33057
Last Modified: 11 Aug 2025Transient DOS in Multi-Mode Call Processor while processing UE policy container.
CVE-2023-33049
Last Modified: 11 Aug 2025Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
CVE-2023-33046
Last Modified: 11 Aug 2025Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
CVE-2024-23304
Last Modified: 4 Jun 2025Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.
CVE-2024-24808
Last Modified: 9 May 2025pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the `get_redirect_url` function when redirecting users at login. This vulnerability has been patched with commit fe94451.
CVE-2024-20828
Last Modified: 21 Nov 2024Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.
CVE-2024-20827
Last Modified: 21 Nov 2024Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.
CVE-2024-20826
Last Modified: 21 Nov 2024Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20825
Last Modified: 15 May 2025Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20824
Last Modified: 21 Nov 2024Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20823
Last Modified: 21 Nov 2024Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20822
Last Modified: 24 Apr 2025Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20820
Last Modified: 21 Nov 2024Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.
CVE-2024-20819
Last Modified: 17 Jun 2025Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
CVE-2024-20818
Last Modified: 17 Jun 2025Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
CVE-2024-20817
Last Modified: 8 May 2025Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
