VYPR

Android SDK

by Google

CVEs (1,657)

  • CVE-2022-20453MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is needed for…

  • CVE-2022-20448MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20426MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20414MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20440MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259918

  • CVE-2022-20439MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Messaging, There has unauthorized provider, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242266172

  • CVE-2022-20438MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259920

  • CVE-2022-20437MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242258929

  • CVE-2022-20425MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20413MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20351MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20399MedSep 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to local information disclosure of network data with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20396MedSep 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2022-20393MedSep 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0887MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0698MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20341MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20332MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20326MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…

  • CVE-2022-20324MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

Page 57 of 83