|
1171
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional e…
|
CWE-20
Improper Input Validation
|
CVE-2026-28578
|
2026-06-3 22:35 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1172
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-28580
|
2026-06-3 22:35 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1173
|
4.0 |
MEDIUM
Local
|
google
|
android
|
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileg…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28581
|
2026-06-3 22:29 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1174
|
3.3 |
LOW
Local
|
google
|
android
|
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution pri…
|
CWE-269
Improper Privilege Management
|
CVE-2026-28586
|
2026-06-3 22:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1175
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-3012
|
2026-06-3 15:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1176
|
8.8 |
HIGH
Network
|
-
|
-
|
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…
|
CWE-78
OS Command
|
CVE-2026-36044
|
2026-06-3 13:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1177
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
|
CWE-416
Use After Free
|
CVE-2026-10000
|
2026-06-3 11:32 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1178
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10008
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1179
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
|
CWE-346
Origin Validation Error
|
CVE-2026-10010
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1180
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Ch…
|
CWE-200
Information Exposure
|
CVE-2026-10011
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|