Latest CVE Feed
-
7.5
HIGHCVE-2024-56446
Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2024-56445
Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-56444
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-56443
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-56442
Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2024-56441
Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2024-56440
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-56439
Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-56438
Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-56437
Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Denial of Service
-
5.9
MEDIUMCVE-2024-54120
Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Race Condition
-
6.9
MEDIUMCVE-2024-47934
Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The Denial of Service situation can be resolved by restarting the man... Read more
Affected Products :- Published: Jan. 08, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-47239
Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
Affected Products : powerscale_onefs- Published: Jan. 08, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2023-52955
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2023-52954
Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2023-52953
Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-56436
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-56435
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-56434
UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2024-50603
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can... Read more
Affected Products : controller- Actively Exploited
- Published: Jan. 08, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection