CVE-2024-0040
published 2024-02-16CVE-2024-0040: In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.95%
78.0th percentile
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 11:0 < 11:2024-02-01 | 11:2024-02-01 |
| platform | frameworks_av | >= 12:0 < 12:2024-02-01 | 12:2024-02-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2024-02-01 | 12L:2024-02-01 |
| platform | frameworks_av | >= 13:0 < 13:2024-02-01 | 13:2024-02-01 |
| platform | frameworks_av | >= 14-next:0 < 14-next:2024-02-01 | 14-next:2024-02-01 |
| platform | frameworks_av | >= 14:0 < 14:2024-02-01 | 14:2024-02-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2024-0040: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0040
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-300007708
vendor_android·2024-02-01·CVSS 7.5
CVE-2024-0040 [HIGH] CVE-2024-0040: Android Security Bulletin 2024-02-01
CVE: CVE-2024-0040
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-300007708
Android Security Bulletin 2024-02-01
CVE: CVE-2024-0040
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-300007708
GHSA
GHSA-3cmq-9cqr-3jc4: In setParameter of MtpPacket
ghsa_unreviewed·2024-02-16
CVE-2024-0040 [HIGH] CWE-122 GHSA-3cmq-9cqr-3jc4: In setParameter of MtpPacket
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0040: In setParameter of MtpPacket
osv·2024-02-01
CVE-2024-0040 CVE-2024-0040: In setParameter of MtpPacket
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Suricata
GPL FTP SITE ZIPCHK overflow attempt
suricata·2010-09-23
CVE-2000-0040 GPL FTP SITE ZIPCHK overflow attempt
GPL FTP SITE ZIPCHK overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET 21 (msg:"GPL FTP SITE ZIPCHK overflow attempt"; flow:established,to_server; content:"SITE"; nocase; content:"ZIPCHK"; distance:1; nocase; isdataat:100,relative; pcre:"/^SITE\s+ZIPCHK\s[^\n]{100}/smi"; reference:cve,2000-0040; classtype:attempted-admin; sid:2101921; rev:8; metadata:created_at 2010_09_23, cve CVE_2000_0040, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/av/+/2ca6c27dc0336fd98f47cfb96dc514efa98e8864https://source.android.com/security/bulletin/2024-02-01https://android.googlesource.com/platform/frameworks/av/+/2ca6c27dc0336fd98f47cfb96dc514efa98e8864https://source.android.com/security/bulletin/2024-02-01
2024-02-16
Published