321
|
- |
|
-
|
-
|
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
New
|
-
|
CVE-2024-49738
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
322
|
- |
|
-
|
-
|
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local es…
New
|
-
|
CVE-2024-49737
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
323
|
- |
|
-
|
-
|
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no addit…
New
|
-
|
CVE-2024-49736
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
324
|
- |
|
-
|
-
|
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to c…
New
|
-
|
CVE-2023-37035
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
325
|
- |
|
-
|
-
|
A code injection vulnerability exists in the Ambari Alert Definition
feature, allowing authenticated users to inject and execute arbitrary
shell commands. The vulnerability arises when defining ale…
New
|
-
|
CVE-2025-23196
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
326
|
- |
|
-
|
-
|
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie
project, allowing an attacker to inject malicious XML entities. This
vulnerability occurs due to insecure parsing of XML input …
New
|
-
|
CVE-2025-23195
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
327
|
- |
|
-
|
-
|
A remote code injection vulnerability exists in the Ambari Metrics and
AMS Alerts feature, allowing authenticated users to inject and execute
arbitrary code. The vulnerability occurs when processin…
New
|
-
|
CVE-2024-51941
|
2025-01-23 00:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
328
|
- |
|
-
|
-
|
The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which cou…
Update
|
-
|
CVE-2024-9020
|
2025-01-23 00:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
329
|
4.3 |
MEDIUM
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows…
|
MapUrlToZone Security Feature Bypass Vulnerability
Update
|
NVD-CWE-noinfo
|
CVE-2025-21329
|
2025-01-23 00:02 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
330
|
4.3 |
MEDIUM
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2025 windows_server_2022_23h2 windows_10_1507 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows…
|
MapUrlToZone Security Feature Bypass Vulnerability
Update
|
NVD-CWE-noinfo
|
CVE-2025-21328
|
2025-01-22 23:59 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|