VYPR

android-x86

by Android X86

CVEs (1,312)

  • CVE-2018-9454MedNov 6, 2018
    risk 0.36cvss 5.5epss 0.00

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions:…

  • CVE-2018-9451MedNov 6, 2018
    risk 0.36cvss 5.5epss 0.00

    In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2018-9444MedNov 6, 2018
    risk 0.36cvss 5.5epss 0.01

    In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interaction is needed for…

  • CVE-2018-9437MedNov 6, 2018
    risk 0.36cvss 5.5epss 0.02

    In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0…

  • CVE-2017-18281MedOct 29, 2018
    risk 0.36cvss 5.5epss 0.00

    A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel

  • CVE-2025-48551MedSep 4, 2025
    risk 0.33cvss 5.0epss 0.00

    In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-26426MedSep 4, 2025
    risk 0.33cvss 5.1epss 0.00

    In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2024-56184MedMar 10, 2025
    risk 0.33cvss 5.1epss 0.00

    In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43090MedNov 13, 2024
    risk 0.33cvss 5.0epss 0.00

    In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-0019MedFeb 16, 2024
    risk 0.33cvss 5.0epss 0.00

    In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User…

  • CVE-2023-21307MedOct 30, 2023
    risk 0.33cvss 5.0epss 0.00

    In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2023-21190MedJun 28, 2023
    risk 0.33cvss 5.0epss 0.00

    In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2022-20394MedOct 11, 2022
    risk 0.33cvss 5.0epss 0.00

    In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-20266MedAug 12, 2022
    risk 0.33cvss 5.0epss 0.00

    In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0973MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0322MedJan 11, 2021
    risk 0.33cvss 5.0epss 0.00

    In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android;…

  • CVE-2020-0093MedMay 14, 2020
    risk 0.33cvss 5.0epss 0.00

    In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2014-7951MedFeb 20, 2020
    risk 0.33cvss 4.6epss 0.01

    Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar archive headers.

  • CVE-2019-9421MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In libandroidfw, there is a possible OOB read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215250

  • CVE-2019-9383MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

Page 59 of 66