Логотип exploitDog
bind:CVE-2024-43093
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-43093

Количество 3

Количество 3

nvd логотип

CVE-2024-43093

около 1 года назад

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-9g9p-59w9-vqqc

около 1 года назад

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2024-09108

больше 1 года назад

Уязвимость компонента Android Framework операционной системы Android, позволяющая нарушителю повысить свои привилегии и получить несанкционированноый доступ к каталогам Android/data, Android/obb, Android/sandbox

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-43093

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-9g9p-59w9-vqqc

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-09108

Уязвимость компонента Android Framework операционной системы Android, позволяющая нарушителю повысить свои привилегии и получить несанкционированноый доступ к каталогам Android/data, Android/obb, Android/sandbox

CVSS3: 9.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу