The tech giant fixed privilege-escalation and model-exfiltration vulnerabilities in Vertex AI that could have allowed attackers to steal or poison custom-built AI models.
A vulnerability, which was classified as problematic, has been found in Google Android 12/13/14/15. This issue affects the function shouldHideDocument of the file ExternalStorageProvider.java. The manipulation leads to Local Privilege Escalation.
The identification of this vulnerability is CVE-2024-43093. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical was found in Google Android 12/12L/13/14/15. This vulnerability affects unknown code of the file AppInfoBase.java. The manipulation leads to permission issues.
This vulnerability was named CVE-2024-43088. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic has been found in umbrel up to 1.2.1. This affects an unknown part of the component Query Parameter Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-49379. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Android 12/12L/13/14/15. It has been declared as problematic. Affected by this vulnerability is the function validateAccountsInternal of the file AccountManagerService.java. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-43086. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Simple Laboratory Management System 1.0. It has been rated as critical. Affected by this issue is the function delete_users of the file Useres.php. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-40443. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Google Android 12/12L/13/14/15. It has been classified as critical. Affected is the function updateInternal of the file MediaProvider.java. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2024-43089. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Google Android 12/12L/13/14/15 and classified as problematic. This issue affects the function getInstalledAccessibilityPreferences of the file AccessibilitySettings.java. The manipulation leads to Local Privilege Escalation.
The identification of this vulnerability is CVE-2024-43087. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in Google Android 12/12L/13/14/15 and classified as problematic. This vulnerability affects the function handleMessage of the file UsbDeviceManager.java. The manipulation leads to Local Privilege Escalation.
This vulnerability was named CVE-2024-43085. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, was found in Google Android 12/12L/13/14/15. This affects the function onReceive of the file AppRestrictionsFragment.java. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2024-43080. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, has been found in Google Android 12/12L/13/14. Affected by this issue is the function mayAdminGrantPermission of the file AdminRestrictedPermissionsUtils.java. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2024-40661. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in Google Android 14/15. Affected by this vulnerability is the function setTransactionState of the file SurfaceFlinger.cpp. The manipulation leads to state issue.
This vulnerability is known as CVE-2024-40660. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in Google Android 12/12L/13/14. Affected is an unknown function. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2024-34719. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Google Android 12/12L/13/14. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-43090. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Google Android 12/12L/13/14/15. It has been declared as problematic. This vulnerability affects the function visitUris. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-43084. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Google Android 12/12L/13/14/15. It has been classified as problematic. This affects the function validate of the file WifiConfigurationUtil.java. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2024-43083. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file music_list.php of the component GET Request Handler. The manipulation of the argument cid leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-0938. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.