6.5

CVSS3.1

CVE-2024-23551 - HCL BigFix Compliance is potentially affected by Oracle database credentials stored at endpoint

Database scanning using username and password stores the credentials inย plaintext or encoded format within files at the endpoint. This has been identified as a significantย security risk. This will lead to exposure of sensitive information for unauthorized access,ย potentially leading to severe conseโ€ฆ

๐Ÿ“… Published: May 7, 2024, 9:46 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2023-40694 - IBM Watson CP4D Data Stores information disclosure

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 264838.

๐Ÿ“… Published: May 7, 2024, 9:09 p.m. ๐Ÿ”„ Last Modified: Aug. 20, 2025, 3:14 a.m.

6.5

CVSS3.1

CVE-2024-23709 -

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 4:25 p.m.

9.8

CVSS3.1

CVE-2024-23708 -

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 6:13 p.m.

7.8

CVSS3.1

CVE-2024-23707 -

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 4:21 p.m.

7.8

CVSS3.1

CVE-2024-23706 -

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 4:42 p.m.

9.8

CVSS3.1

CVE-2024-23705 -

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 6:13 p.m.

7.8

CVSS3.1

CVE-2024-0043 -

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: March 29, 2025, 12:15 a.m.

7.8

CVSS3.1

CVE-2024-0025 -

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 4:48 p.m.

7.8

CVSS3.1

CVE-2024-0024 -

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

๐Ÿ“… Published: May 7, 2024, 9:03 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 4:48 p.m.
Total resulsts: 349182
Page 9953 of 34,919
ยซ previous page ยป next page
Filters