CVE-2024-47012
https://notcve.org/view.php?id=CVE-2024-47012
This could lead to local escalation of privilege with no additional execution privileges needed. • https://source.android.com/security/bulletin/pixel/2024-10-01 • CWE-276: Incorrect Default Permissions •
CVE-2024-44098
https://notcve.org/view.php?id=CVE-2024-44098
In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. • https://source.android.com/security/bulletin/pixel/2024-10-01 • CWE-415: Double Free •
CVE-2024-48931 – ZimaOS Arbitrary File Read via Parameter Manipulation
https://notcve.org/view.php?id=CVE-2024-48931
This vulnerability exposes critical system data and poses a high risk for privilege escalation or system compromise. • https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-hjw2-9gq5-qgwj https://youtu.be/FyIfcmCyDXs • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2024-45261
https://notcve.org/view.php?id=CVE-2024-45261
Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control. • https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Bypassing%20Login%20Mechanism%20with%20Passwordless%20User%20Login.md • CWE-863: Incorrect Authorization •
CVE-2024-10183 – Arbitrary File Write Vulnerability in Jamf Remote Assist Leading to Privilege Escalation
https://notcve.org/view.php?id=CVE-2024-10183
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems. • https://learn.jamf.com/en-US/bundle/jamf-remote-assist-release-notes/page/Jamf_Remote_Assist_Release_History.html#ariaid-title4 • CWE-276: Incorrect Default Permissions •