CVE-2024-0042
published 2024-05-07CVE-2024-0042: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.5th percentile
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59j5-r3pj-3q9p: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto
ghsa_unreviewed·2024-05-07
CVE-2024-0042 [MEDIUM] CWE-295 GHSA-59j5-r3pj-3q9p: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0042: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto
osv·2024-04-01
CVE-2024-0042 CVE-2024-0042: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-0042: Widevine DRM
vendor_android·2024-04-01·CVSS 7.8
CVE-2024-0042 [HIGH] CVE-2024-0042: Widevine DRM
Android Security Bulletin 2024-04-01
CVE: CVE-2024-0042
Severity: HIGH
Component: Widevine DRM
References: A-312543200
*
Suricata
GPL WEB_SERVER Tomcat null byte directory listing attempt
suricata·2010-09-23
CVE-2003-0042 GPL WEB_SERVER Tomcat null byte directory listing attempt
GPL WEB_SERVER Tomcat null byte directory listing attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL WEB_SERVER Tomcat null byte directory listing attempt"; flow:established,to_server; http.uri; content:"|00|.jsp"; reference:bugtraq,2518; reference:bugtraq,6721; reference:cve,2003-0042; classtype:web-application-attack; sid:2102061; rev:9; metadata:created_at 2010_09_23, cve CVE_2003_0042, signature_severity Unknown, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
2024-05-07
Published