Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-31677: record/luowice.md at main · zzh-newlearner/record

Insecure permissions in luowice 3.5.18 allow attackers to view information for other alarm devices via modification of the eseeid parameter.

CVE
#vulnerability#android

Permalink

Cannot retrieve contributors at this time

com.generalcomp.luowice 3.5.18 has Insecure Permission****Vulnerability Type:

Insecure Permission

Vulnerability Version:

3.5.18

Recurring environment

≥Android 7.0

Vulnerability Description AND recurrence:

Modify “eseeid” to any other field and use BASE64 encoding to access alarm information for different devices The “img_url” in the response body is decoded by BASE64 and is the image taken in the alarm message of the device, which is not further used for ethical reasons

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907