CVE-2024-40675
published 2025-01-28CVE-2024-40675: In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
23.3th percentile
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-40675: In parseUriInternal of Intent
osv·2025-01-28·CVSS 7.5
CVE-2024-40675 [HIGH] CVE-2024-40675: In parseUriInternal of Intent
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-wq23-xq9q-wf8w: In parseUriInternal of Intent
ghsa_unreviewed·2025-01-28
CVE-2024-40675 [HIGH] CWE-835 GHSA-wq23-xq9q-wf8w: In parseUriInternal of Intent
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-40675: Android Security Bulletin 2024-10-01
CVE: CVE-2024-40675
Severity: HIGH
Type: DoS
Affected AOSP versions: 12, 12L, 13, 14
References: A-318683126
vendor_android·2024-10-01·CVSS 7.5
CVE-2024-40675 [HIGH] CVE-2024-40675: Android Security Bulletin 2024-10-01
CVE: CVE-2024-40675
Severity: HIGH
Type: DoS
Affected AOSP versions: 12, 12L, 13, 14
References: A-318683126
Android Security Bulletin 2024-10-01
CVE: CVE-2024-40675
Severity: HIGH
Type: DoS
Affected AOSP versions: 12, 12L, 13, 14
References: A-318683126
No detection rules found.
No public exploits indexed.
2025-01-28
Published