mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-07 13:36:56 +00:00
25 lines
906 B
JSON
25 lines
906 B
JSON
![]() |
{
|
||
|
"id": "CVE-2024-40673",
|
||
|
"sourceIdentifier": "security@android.com",
|
||
|
"published": "2025-01-28T20:15:49.530",
|
||
|
"lastModified": "2025-01-28T20:15:49.530",
|
||
|
"vulnStatus": "Received",
|
||
|
"cveTags": [],
|
||
|
"descriptions": [
|
||
|
{
|
||
|
"lang": "en",
|
||
|
"value": "In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation."
|
||
|
}
|
||
|
],
|
||
|
"metrics": {},
|
||
|
"references": [
|
||
|
{
|
||
|
"url": "https://android.googlesource.com/platform/libcore/+/b17fd2f8fe468e7d32e713b442f610cd33e4e7a9",
|
||
|
"source": "security@android.com"
|
||
|
},
|
||
|
{
|
||
|
"url": "https://source.android.com/security/bulletin/2024-10-01",
|
||
|
"source": "security@android.com"
|
||
|
}
|
||
|
]
|
||
|
}
|