In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure w…
In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no …
In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosu…
In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execu…
In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure…
In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of priv…
In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional exe…
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution pri…
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution pri…
In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information dis…
In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with …
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escala…
In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and g…
An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows …
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows a…
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access re…
<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker w…
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-…
managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to…
A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could …
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Str…
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute…
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must ha…
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Marke…
SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify…
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an atta…
In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This c…
In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure …
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerab…
An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the mo…