Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-19 CVE-2024-51669 Cross-Site Request Forgery (CSRF) vulnerability in Vivwebsolutions Dynamic Widgets
Cross-Site Request Forgery (CSRF) vulnerability in Vivwebs Dynamic Widgets.This issue affects Dynamic Widgets: from n/a through 1.6.4.
network
low complexity
vivwebsolutions CWE-352
8.8
2024-11-19 CVE-2018-9365 Out-of-bounds Read vulnerability in Google Android
In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check.
network
low complexity
google CWE-125
8.8
2024-11-19 CVE-2018-9364 Unspecified vulnerability in Google Android
In the LG LAF component, there is a special command that allowed modification of certain partitions.
network
low complexity
google
7.5
2024-11-19 CVE-2018-9366 Integer Overflow or Wraparound vulnerability in Google Android
In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2024-11-19 CVE-2018-9367 Out-of-bounds Write vulnerability in Google Android
In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation.
local
low complexity
google CWE-787
7.8
2024-11-19 CVE-2018-9368 Out-of-bounds Write vulnerability in Google Android
In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies.
local
low complexity
google CWE-787
7.8
2024-11-19 CVE-2018-9369 Unspecified vulnerability in Google Android
In bootloader there is fastboot command allowing user specified kernel command line arguments.
local
low complexity
google
7.3
2024-11-19 CVE-2018-9370 Out-of-bounds Write vulnerability in Google Android
In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check.
local
low complexity
google CWE-787
7.3
2024-11-19 CVE-2024-52360 IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection.
network
low complexity
7.6
2024-11-19 CVE-2018-9339 Type Confusion vulnerability in Google Android 8.0/8.1
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion.
local
low complexity
google CWE-843
7.8