Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7676-xq8c-838g

Опубликовано: 28 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 4%
0.00019
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 года назад

In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 4%
0.00019
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-908