VYPR

Android SDK

by Google

CVEs (1,772)

  • CVE-2021-0330HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0329HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-0328HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0327HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0302HigFeb 10, 2021
    risk 0.51cvss 7.8epss 0.01

    In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0318HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2021-0306HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation…

  • CVE-2020-27054HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android…

  • CVE-2020-27052HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-27051HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-27050HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In rw_i93_send_cmd_write_multi_blocks of rw_i93.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-27049HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-27045HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In CE_SendRawFrame of ce_main.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-27044HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In restartWrite of Parcel.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0486HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0485HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0479HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with no additional execution privileges…

  • CVE-2020-0475HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-0016HigDec 14, 2020
    risk 0.51cvss 7.8epss 0.00

    In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID:…

  • CVE-2020-0458HigDec 14, 2020
    risk 0.51cvss 7.8epss 0.01

    In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for…

Page 27 of 89