5.9
CVE-2020-4874 - IBM Cognos Controller information disclosure
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837.
8.8
CVE-2023-37407 - IBM Aspera Orchestrator command execution
IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 260116.
2.8
CVE-2024-3480 -
An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.
2.8
CVE-2024-3479 -
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.
6.3
CVE-2024-3109 -
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.
5.5
CVE-2024-3108 -
An implicit intent vulnerability was reported for Motorolaβs Time Weather Widget application that could allow a local application to acquire the location of the device without authorization.Β
6.5
CVE-2023-41830 -
An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.Β
4.4
CVE-2023-41828 -
An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.Β Β
5.1
CVE-2023-41826 -
A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission.Β
2.8
CVE-2023-41825 -
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.Β