Vulnerabilities (CVE)

Filtered by CWE-20
Total 10395 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23706 1 Google 1 Android 2024-12-17 N/A 7.8 HIGH
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-0045 1 Google 1 Android 2024-12-17 N/A 6.5 MEDIUM
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2020-12487 2024-12-17 N/A 7.0 HIGH
Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.
CVE-2024-0031 1 Google 1 Android 2024-12-16 N/A 9.8 CRITICAL
In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-23717 1 Google 1 Android 2024-12-16 N/A 8.8 HIGH
In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-0021 1 Google 1 Android 2024-12-16 N/A 7.8 HIGH
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2024-10972 2024-12-16 N/A 7.3 HIGH
Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread changing the memory’s access right under the control of the user-mode application. This is due to verification only being performed at the beginning of the routine allowing the userspace to change page permissions half way through the routine.  A valid workaround is a rule to detect unauthorized loading of winpmem outside incident response operations.
CVE-2018-12123 1 Nodejs 1 Node.js 2024-12-13 4.3 MEDIUM 4.3 MEDIUM
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.
CVE-2024-54109 1 Huawei 1 Harmonyos 2024-12-12 N/A 6.5 MEDIUM
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-54108 1 Huawei 1 Harmonyos 2024-12-12 N/A 6.5 MEDIUM
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-54107 1 Huawei 1 Harmonyos 2024-12-12 N/A 7.1 HIGH
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-43052 1 Qualcomm 182 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 179 more 2024-12-12 N/A 7.8 HIGH
Memory corruption while processing API calls to NPU with invalid input.
CVE-2024-12401 2024-12-12 N/A 4.4 MEDIUM
A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in a Secret resource, to use large amounts of CPU in the cert-manager controller pod to effectively create a denial-of-service (DoS) vector for the cert-manager in the cluster.
CVE-2023-31366 1 Amd 1 Uprof 2024-12-12 N/A 3.3 LOW
Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.
CVE-2024-32989 1 Huawei 2 Emui, Harmonyos 2024-12-11 N/A 3.3 LOW
Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-32990 1 Huawei 2 Emui, Harmonyos 2024-12-11 N/A 6.1 MEDIUM
Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-32992 1 Huawei 2 Emui, Harmonyos 2024-12-11 N/A 7.5 HIGH
Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-11737 2024-12-11 N/A 9.8 CRITICAL
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.
CVE-2024-12353 1 Razormist 1 Phone Contact Manager System 2024-12-10 1.7 LOW 3.3 LOW
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation of the argument name leads to improper input validation. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
CVE-2024-12355 1 Razormist 1 Phone Contact Manager System 2024-12-10 1.7 LOW 3.3 LOW
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of the file ContactBook.cpp. The manipulation leads to improper input validation. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.