Skip to main content

Threats Tagged 'cwe-925'

View all threats tagged with 'cwe-925'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-925

Threats Tagged 'cwe-925'

Click on any threat for detailed analysis and mitigation recommendations

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe `content_type`, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Join the discussion

CVE-2026-20988 is a medium-severity vulnerability affecting Samsung Mobile devices prior to the SMR March 2026 Release 1. It involves improper verification of intent by a broadcast receiver in the Settings app, allowing a local attacker with limited privileges to launch arbitrary activities with elevated Settings privileges. Exploitation requires user interaction and local access, meaning the attacker must trick the user into triggering the malicious intent. The vulnerability stems from CWE-925, indicating improper verification of intent, which can lead to privilege escalation within the device. No known exploits are currently reported in the wild. The CVSS 4.0 base score is 6.8, reflecting moderate impact on confidentiality and integrity with limited attack vector and user interaction required. Organizations using Samsung Mobile devices should prioritize patching once updates are available and educate users to avoid suspicious prompts. This vulnerability primarily affects countries with high Samsung mobile device penetration and significant mobile user bases.

Join the discussion

Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Join the discussion

Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Join the discussion

Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

Join the discussion

Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-925
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses