VYPR

android-x86

by Android X86

CVEs (1,312)

  • CVE-2024-32915MedJun 13, 2024
    risk 0.28cvss 4.3epss 0.00

    In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

  • CVE-2020-0499MedDec 15, 2020
    risk 0.28cvss 4.3epss 0.04

    In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2023-21178MedJun 28, 2023
    risk 0.27cvss 4.1epss 0.00

    In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20541MedDec 16, 2022
    risk 0.27cvss 4.2epss 0.00

    In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2026-0142MedJun 16, 2026
    risk 0.26cvss 4.0epss 0.00

    In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0108MedMar 10, 2026
    risk 0.26cvss 4.0epss 0.00

    The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26425MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with…

  • CVE-2025-26424MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-49739MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26417MedAug 26, 2025
    risk 0.26cvss 4.0epss 0.00

    In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction…

  • CVE-2025-22413MedAug 26, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-0083MedAug 26, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-49895LowSep 8, 2026
    risk 0.23cvss 3.5epss 0.00

    In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2026-45525LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-45521LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-45519LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28660LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28638LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28630LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28623LowSep 8, 2026
    risk 0.21cvss 3.3epss 0.00

    In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…