Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Damiano Melotti

Researcher fromQuarkslab
#18576of 53,635
14.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-18739
6.7
2024-03-04
Unknown · Little Kernel · CVE-2024-20831
**Name of the Vulnerable Software and Affected Versions** Little Kernel in bootloader versions prior to SMR Mar-2024 Release 1 **Description** The issue is a stack overflow in the Little Kernel in the bootloader, which allows local privileged attackers to execute arbitrary code. This can be exploited by privileged attackers. **Recommendations** For versions prior to SMR Mar-2024 Release 1, update to SMR Mar-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the bootloader to minimize the risk of exploitation.
PT-2024-18726
7.8
2024-02-05
Unknown · Libsthmbc.So · CVE-2024-20819
**Name of the Vulnerable Software and Affected Versions** libsthmbc.so versions prior to SMR Feb-2024 Release 1 **Description** The issue is related to Out-of-bounds Write vulnerabilities in the `svc1td vld plh ap` function of `libsthmbc.so`. This allows local attackers to trigger a buffer overflow. **Recommendations** For versions prior to SMR Feb-2024 Release 1, update to the SMR Feb-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the `svc1td vld plh ap` function until a patch is available.