VYPR

android-x86

by Android X86

CVEs (1,312)

  • CVE-2023-21398HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21389HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21378HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21375HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21373HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21372HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21355HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21351HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21343HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21342HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-21341HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21324HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2021-39810HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution…

  • CVE-2023-40140HigOct 27, 2023
    risk 0.51cvss 7.8epss 0.00

    In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-35687HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35670HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-35669HigSep 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-35689HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21281HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed. User interaction is not…

  • CVE-2023-21272HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Page 19 of 66