2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49745 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to ... |
| CVE-2024-49744 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit... |
| CVE-2024-49742 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac... |
| CVE-2024-49738 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege... |
| CVE-2024-49737 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities ... |
| CVE-2024-49736 | MEDIUM | 5.5 | 0.1% | Jan 21, 2025 | In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo... |
| CVE-2024-49735 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul... |
| CVE-2024-49734 | HIGH | 7.5 | 0.3% | Jan 21, 2025 | In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic... |
| CVE-2024-49733 | MEDIUM | 5.5 | 0.1% | Jan 21, 2025 | In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to ... |
| CVE-2024-49732 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c... |
| CVE-2024-49724 | HIGH | 7 | 0.1% | Jan 21, 2025 | In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected ... |
| CVE-2024-43771 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2024-43770 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co... |
| CVE-2024-43765 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou... |
| CVE-2024-43763 | MEDIUM | 6.5 | 0.1% | Jan 21, 2025 | In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul... |
| CVE-2024-43096 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could... |
| CVE-2024-43095 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This co... |
| CVE-2024-34730 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in... |
| CVE-2024-24443 | MEDIUM | 6.5 | 0.3% | Jan 21, 2025 | An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface ... |
| CVE-2024-24428 | HIGH | 7.5 | 0.5% | Jan 21, 2025 | A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv... |
| CVE-2024-24427 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service ... |
| CVE-2024-24424 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321... |
| CVE-2024-24423 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24422 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co... |
| CVE-2024-24421 | CRITICAL | 9.8 | 0.9% | Jan 21, 2025 | A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now