CVE-2024-29745

MEDIUM KEV

Uninitialized Data - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-29745 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 4, 2024.

Description

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 42.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2024-04-04
VulnCheck KEV 2024-04-02
InTheWild.io 2024-04-02
ENISA EUVD EUVD-2024-26740
CWE
CWE-908
Status published
Products (1)
google/android
Published Apr 05, 2024
KEV Added Apr 04, 2024
Tracked Since Feb 18, 2026