2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49745HIGH7.8In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to ...
CVE-2024-49744HIGH7.8In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit...
CVE-2024-49742HIGH7.8In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac...
CVE-2024-49738HIGH7.8In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege...
CVE-2024-49737HIGH7.8In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities ...
CVE-2024-49736MEDIUM5.5In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo...
CVE-2024-49735HIGH7.8In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul...
CVE-2024-49734HIGH7.5In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic...
CVE-2024-49733MEDIUM5.5In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to ...
CVE-2024-49732HIGH7.8In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c...
CVE-2024-49724HIGH7In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected ...
CVE-2024-43771HIGH8.8In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2024-43770HIGH8.8In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co...
CVE-2024-43765HIGH7.8In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou...
CVE-2024-43763MEDIUM6.5In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul...
CVE-2024-43096HIGH8.8In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could...
CVE-2024-43095HIGH7.8In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This co...
CVE-2024-34730HIGH7.8In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in...
CVE-2024-24443MEDIUM6.5An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface ...
CVE-2024-24428HIGH7.5A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv...
CVE-2024-24427HIGH7.5A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service ...
CVE-2024-24424HIGH7.5A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321...
CVE-2024-24423HIGH7.5The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co...
CVE-2024-24422HIGH7.5The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co...
CVE-2024-24421CRITICAL9.8A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now