CVE-2024-32900
https://notcve.org/view.php?id=CVE-2024-32900
13 Jun 2024 — This could lead to local escalation of privilege from hal_camera_default SELinux label with no additional execution privileges needed. ... Esto podría llevar a una escalada local de privilegios desde la etiqueta hal_camera_default SELinux sin necesidad de privilegios de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-416: Use After Free CWE-667: Improper Locking •
CVE-2024-32899
https://notcve.org/view.php?id=CVE-2024-32899
13 Jun 2024 — This could lead to local escalation of privilege to TEE with no additional execution privileges needed. ... Esto podría llevar a una escalada local de privilegios a TEE sin necesidad de privilegios de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-269: Improper Privilege Management CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2024-32896 – Android Pixel Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2024-32896
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. ... Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-783: Operator Precedence Logic Error •
CVE-2024-32895
https://notcve.org/view.php?id=CVE-2024-32895
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-787: Out-of-bounds Write •
CVE-2024-32892
https://notcve.org/view.php?id=CVE-2024-32892
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2024-32891
https://notcve.org/view.php?id=CVE-2024-32891
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2024-29787
https://notcve.org/view.php?id=CVE-2024-29787
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-416: Use After Free •
CVE-2024-29784
https://notcve.org/view.php?id=CVE-2024-29784
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-06-01 • CWE-190: Integer Overflow or Wraparound CWE-269: Improper Privilege Management •
CVE-2024-32929
https://notcve.org/view.php?id=CVE-2024-32929
13 Jun 2024 — This could lead to local escalation of privilege with no additional execution privileges needed. ... Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://source.android.com/security/bulletin/pixel/2024-05-01 • CWE-416: Use After Free •
CVE-2024-37857 – Lost and Found Information System 1.0 SQL Injection
https://notcve.org/view.php?id=CVE-2024-37857
13 Jun 2024 — SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php. • https://packetstorm.news/files/id/179080 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •