Threats Tagged 'cwe-925'
View all threats tagged with 'cwe-925'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-925'
Click on any threat for detailed analysis and mitigation recommendations
0 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe `content_type`, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch. Join the discussion | CVE Database V5 | 03/23/2026, 23:21:29 UTC Added: 03/24/2026, 00:02:47 UTC |
0 CVE-2026-20988 is a medium-severity vulnerability affecting Samsung Mobile devices prior to the SMR March 2026 Release 1. It involves improper verification of intent by a broadcast receiver in the Settings app, allowing a local attacker with limited privileges to launch arbitrary activities with elevated Settings privileges. Exploitation requires user interaction and local access, meaning the attacker must trick the user into triggering the malicious intent. The vulnerability stems from CWE-925, indicating improper verification of intent, which can lead to privilege escalation within the device. No known exploits are currently reported in the wild. The CVSS 4.0 base score is 6.8, reflecting moderate impact on confidentiality and integrity with limited attack vector and user interaction required. Organizations using Samsung Mobile devices should prioritize patching once updates are available and educate users to avoid suspicious prompts. This vulnerability primarily affects countries with high Samsung mobile device penetration and significant mobile user bases. Join the discussion | CVE Database V5 | 03/16/2026, 04:31:53 UTC Added: 03/16/2026, 04:50:59 UTC |
0 Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. Join the discussion | CVE Database V5 | 09/03/2025, 06:05:46 UTC Added: 09/03/2025, 06:17:51 UTC |
0 Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. Join the discussion | CVE Database V5 | 09/03/2025, 06:05:44 UTC Added: 09/03/2025, 06:17:51 UTC |
0 Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. Join the discussion | CVE Database V5 | 09/03/2025, 06:05:43 UTC Added: 09/03/2025, 06:17:51 UTC |
0 Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM. Join the discussion | CVE Database V5 | 09/03/2025, 06:05:32 UTC Added: 09/03/2025, 06:17:50 UTC |
Showing 1 to 6 of 6 results