2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38402 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. |
| CVE-2024-38401 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption while processing concurrent IOCTL calls. |
| CVE-2024-33060 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. |
| CVE-2024-33057 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing the multi-link element Control field when common information length check is missing before ... |
| CVE-2024-33054 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. |
| CVE-2024-33052 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. |
| CVE-2024-33051 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33050 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing... |
| CVE-2024-33048 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| CVE-2024-33047 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when the captureRead QDCM command is invoked from user-space. |
| CVE-2024-33045 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| CVE-2024-33042 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. |
| CVE-2024-33038 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. |
| CVE-2024-33035 | HIGH | 8.4 | 0.1% | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. |
| CVE-2024-23365 | HIGH | 8.4 | 0.1% | Sep 2, 2024 | Memory corruption while releasing shared resources in MinkSocket listener thread. |
| CVE-2024-23364 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Eleme... |
| CVE-2024-23362 | HIGH | 7.1 | 0.1% | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
| CVE-2024-23359 | HIGH | 8.2 | 0.3% | Sep 2, 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
| CVE-2024-23358 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem. |
| CVE-2024-7871 | HIGH | 8.7 | 0.5% | Sep 2, 2024 | SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenti... |
| CVE-2024-43776 | HIGH | 8.8 | 0.5% | Sep 2, 2024 | SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated us... |
| CVE-2024-43775 | HIGH | 8.8 | 0.5% | Sep 2, 2024 | SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authe... |
| CVE-2024-43774 | HIGH | 8.8 | 0.5% | Sep 2, 2024 | SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow... |
| CVE-2024-41160 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2024-41157 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now