CVE-2024-1591 – Privilege Management for Windows < 24.1 Information Leak
https://notcve.org/view.php?id=CVE-2024-1591
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues. Antes de la versión 24.1, un atacante autenticado local puede ver Sysvol cuando Privilege Management para Windows está configurado para usar una política de GPO. Esto les permite ver la política y potencialmente encontrar problemas de configuración. • https://www.beyondtrust.com/trust-center/security-advisories/bt24-02 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-40085
https://notcve.org/view.php?id=CVE-2023-40085
This could lead to local information disclosure with no additional execution privileges needed. • https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/ed6ee1f7eca7b33160e36ac6d730a9ef395ca4f1 https://source.android.com/security/bulletin/2024-01-01 • CWE-125: Out-of-bounds Read •
CVE-2024-0040
https://notcve.org/view.php?id=CVE-2024-0040
This could lead to remote information disclosure with no additional execution privileges needed. • https://android.googlesource.com/platform/frameworks/av/+/2ca6c27dc0336fd98f47cfb96dc514efa98e8864 https://source.android.com/security/bulletin/2024-02-01 • CWE-122: Heap-based Buffer Overflow •
CVE-2024-0037
https://notcve.org/view.php?id=CVE-2024-0037
This could lead to local information disclosure with User execution privileges needed. • https://android.googlesource.com/platform/frameworks/base/+/55fc00a0788ea0995fe0851616b9ac21710a2931 https://source.android.com/security/bulletin/2024-02-01 •
CVE-2024-0030
https://notcve.org/view.php?id=CVE-2024-0030
This could lead to local information disclosure with no additional execution privileges needed. • https://android.googlesource.com/platform/packages/modules/Bluetooth/+/57b823f4f758e2ef530909da07552b5aa80c6a7d https://source.android.com/security/bulletin/2024-02-01 • CWE-125: Out-of-bounds Read •