βΌ CVE-2022-24003 βΌ
π Read
via "National Vulnerability Database".
Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24002 βΌ
π Read
via "National Vulnerability Database".
Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22785 βΌ
π Read
via "National Vulnerability Database".
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)π Read
via "National Vulnerability Database".
βΌ CVE-2022-22292 βΌ
π Read
via "National Vulnerability Database".
Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39663 βΌ
π Read
via "National Vulnerability Database".
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-200682135π Read
via "National Vulnerability Database".
βΌ CVE-2021-39619 βΌ
π Read
via "National Vulnerability Database".
In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-197399948π Read
via "National Vulnerability Database".
βΌ CVE-2022-23431 βΌ
π Read
via "National Vulnerability Database".
An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24000 βΌ
π Read
via "National Vulnerability Database".
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22787 βΌ
π Read
via "National Vulnerability Database".
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)π Read
via "National Vulnerability Database".
βΌ CVE-2021-39665 βΌ
π Read
via "National Vulnerability Database".
In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-204077881π Read
via "National Vulnerability Database".
βΌ CVE-2022-23999 βΌ
π Read
via "National Vulnerability Database".
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22802 βΌ
π Read
via "National Vulnerability Database".
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)π Read
via "National Vulnerability Database".
βΌ CVE-2021-4046 βΌ
π Read
via "National Vulnerability Database".
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0562 βΌ
π Read
via "National Vulnerability Database".
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.π Read
via "National Vulnerability Database".
βΌ CVE-2021-4035 βΌ
π Read
via "National Vulnerability Database".
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39675 βΌ
π Read
via "National Vulnerability Database".
In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-205729183π Read
via "National Vulnerability Database".
βΌ CVE-2022-23995 βΌ
π Read
via "National Vulnerability Database".
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.π Read
via "National Vulnerability Database".
βΌ CVE-2021-22796 βΌ
π Read
via "National Vulnerability Database".
A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)π Read
via "National Vulnerability Database".
βΌ CVE-2020-14521 βΌ
π Read
via "National Vulnerability Database".
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0185 βΌ
π Read
via "National Vulnerability Database".
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.π Read
via "National Vulnerability Database".
βΌ CVE-2021-39677 βΌ
π Read
via "National Vulnerability Database".
In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is Γ’β¬ΛzeroΓ’β¬β’ in size.Product: AndroidVersions: Android-11Android ID: A-205097028π Read
via "National Vulnerability Database".