CVE-2024-43764
published 2025-01-03CVE-2024-43764: In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.08%
0.4th percentile
In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
ghsa·2025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.
GHSA
GHSA-2vvg-qw4w-m46v: In onPrimaryClipChanged of ClipboardListener
ghsa_unreviewed·2025-01-03
CVE-2024-43764 [HIGH] GHSA-2vvg-qw4w-m46v: In onPrimaryClipChanged of ClipboardListener
In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2024-43764: Android Security Bulletin 2024-12-01
CVE: CVE-2024-43764
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14
References: A-317048495
vendor_android·2024-12-01·CVSS 7.8
CVE-2024-43764 [HIGH] CVE-2024-43764: Android Security Bulletin 2024-12-01
CVE: CVE-2024-43764
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14
References: A-317048495
Android Security Bulletin 2024-12-01
CVE: CVE-2024-43764
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14
References: A-317048495
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-03
Published