Latest CVE Feed
-
5.5
MEDIUMCVE-2023-4753
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.... Read more
- Published: Sep. 21, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-27557
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.... Read more
- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-49135
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.... Read more
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24882
Microsoft OneDrive for Android Information Disclosure Vulnerability... Read more
Affected Products : onedrive- Published: Mar. 14, 2023
- Modified: Feb. 28, 2025
-
5.5
MEDIUMCVE-2021-44992
There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-50442
Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryption temporarily. (This modification can, however, be detected, as describe... Read more
Affected Products : zonecentral- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-50974
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2023-52350
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 27, 2025
-
5.5
MEDIUMCVE-2022-20019
In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP... Read more
- Published: Jan. 04, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-20115
In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution privile... Read more
Affected Products : android- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20129
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. ... Read more
Affected Products : android- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46498
Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_wswebsocketObjFree in src/jsiWebSocket.c. This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : jsish- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46532
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via exec_expr at src/mjs_exec.c. This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : mjs- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-30942
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20426
In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is... Read more
Affected Products : android- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2022-20438
In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259920... Read more
Affected Products : android- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-7043
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.... Read more
- Published: Jan. 31, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20476
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is ... Read more
Affected Products : android- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2022-37352
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Mar. 29, 2023
- Modified: Feb. 18, 2025
-
5.5
MEDIUMCVE-2022-37375
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Mar. 29, 2023
- Modified: Nov. 27, 2024