peter bassill · operator
$ cve CVE-2024-29745 JSON

CVE-2024-29745 KEV

5.5
MEDIUM · CVSS 3.1 · EPSS 0.5% (pctl 39)

Patch first

On CISA KEV — known exploited in the wild, due 2024-04-25.

Description

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS0.48% — more likely to be exploited than 39% of all CVEs
WeaknessCWE-908
On CISA KEVyes — remediate by 2024-04-25
Public exploitnone known
Published2024-04-05
Last modified2026-06-17

CISA KEV

NameAndroid Pixel Information Disclosure Vulnerability
Added2024-04-04
Due2024-04-25
Vendor / productAndroid / Pixel
Ransomware usenone reported

Affected (1)

VendorProduct
googleandroid

References

→ the Explorer  ·  watch your stack  ·  NVD