The Wayback Machine - http://web.archive.org/web/20241216151933/https://nvd.nist.gov/
U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2023-40105 - In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interactio... read CVE-2023-40105
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 5.5 MEDIUM

  • CVE-2023-40106 - In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti... read CVE-2023-40106
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 7.8 HIGH

  • CVE-2023-40107 - In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 7.8 HIGH

  • CVE-2023-25922 - IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.
    Published: February 28, 2024; 5:15:25 PM -0500

    V3.1: 8.8 HIGH

  • CVE-2023-40110 - In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita... read CVE-2023-40110
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 7.8 HIGH

  • CVE-2023-25925 - IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.
    Published: February 28, 2024; 5:15:25 PM -0500

    V3.1: 8.8 HIGH

  • CVE-2023-40111 - In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges ne... read CVE-2023-40111
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 7.8 HIGH

  • CVE-2023-25921 - IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.
    Published: February 28, 2024; 8:38:24 PM -0500

    V3.1: 8.8 HIGH

  • CVE-2023-40112 - In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed... read CVE-2023-40112
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 5.5 MEDIUM

  • CVE-2023-40113 - In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne... read CVE-2023-40113
    Published: February 15, 2024; 6:15:08 PM -0500

    V3.1: 5.5 MEDIUM

  • CVE-2023-25926 - IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information... read CVE-2023-25926
    Published: February 28, 2024; 8:38:24 PM -0500

    V3.1: 8.2 HIGH

  • CVE-2024-44853 - Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().
    Published: December 06, 2024; 5:15:21 PM -0500

    V3.1: 7.5 HIGH

  • CVE-2024-44854 - Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().
    Published: December 06, 2024; 5:15:21 PM -0500

    V3.1: 7.5 HIGH

  • CVE-2024-44855 - Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().
    Published: December 06, 2024; 5:15:21 PM -0500

    V3.1: 7.5 HIGH

  • CVE-2024-44856 - Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().
    Published: December 06, 2024; 5:15:21 PM -0500

    V3.1: 7.5 HIGH

  • CVE-2024-41644 - Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.
    Published: December 06, 2024; 5:15:20 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2024-41645 - Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.
    Published: December 06, 2024; 5:15:20 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2024-41646 - Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.
    Published: December 06, 2024; 5:15:20 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2024-41647 - Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.
    Published: December 06, 2024; 5:15:20 PM -0500

    V3.1: 9.8 CRITICAL

  • CVE-2024-41648 - Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.
    Published: December 06, 2024; 5:15:20 PM -0500

    V3.1: 9.8 CRITICAL

Created September 20, 2022 , Updated August 27, 2024