CVE-2024-20114
https://notcve.org/view.php?id=CVE-2024-20114
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20113
https://notcve.org/view.php?id=CVE-2024-20113
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20111
https://notcve.org/view.php?id=CVE-2024-20111
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20110
https://notcve.org/view.php?id=CVE-2024-20110
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20109
https://notcve.org/view.php?id=CVE-2024-20109
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20108
https://notcve.org/view.php?id=CVE-2024-20108
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20106
https://notcve.org/view.php?id=CVE-2024-20106
04 Nov 2024 — This could lead to local escalation of privilege with System execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2024-20104
https://notcve.org/view.php?id=CVE-2024-20104
04 Nov 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/November-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-48336
https://notcve.org/view.php?id=CVE-2024-48336
04 Nov 2024 — The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. • https://github.com/canyie/MagiskEoP • CWE-829: Inclusion of Functionality from Untrusted Control Sphere •
CVE-2024-35141 – IBM Security Verify Access privilege escalation
https://notcve.org/view.php?id=CVE-2024-35141
04 Nov 2024 — IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM Security Verify Access Docker 10.0.0 a 10.0.6 podría permitir que un usuario local aumente sus privilegios debido a la ejecución de privilegios innecesarios. IBM Security Verify Access versions prior to 10.0.8 suffer from authentication bypass, reuse of private keys, local privilege escalation, weak settings, outdated... • https://packetstorm.news/files/id/182466 • CWE-250: Execution with Unnecessary Privileges •