Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-10-07
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-10-07
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
CVSS Score
7.8
EPSS Score
0.001
Published
2024-10-07
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-10-07
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1630.
CVSS Score
4.4
EPSS Score
0.001
Published
2024-10-07
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-10-07
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-10-07
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
CVSS Score
9.8
EPSS Score
0.003
Published
2024-10-07
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.
CVSS Score
9.8
EPSS Score
0.003
Published
2024-10-07
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; Issue ID: MSV-1601.
CVSS Score
4.9
EPSS Score
0.003
Published
2024-10-07


Contact Us

Shodan ® - All rights reserved