VYPR

Android

by Google

CVEs (8,504)

  • CVE-2018-9369HigNov 19, 2024
    risk 0.47cvss 7.3epss 0.00

    In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-31331HigJul 9, 2024
    risk 0.47cvss 7.3epss 0.00

    In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-31324HigJul 9, 2024
    risk 0.47cvss 7.3epss 0.00

    In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode first and then rotating it to landscape mode. This could lead to local escalation of privilege with User execution privileges needed. User…

  • CVE-2024-20057HigMay 6, 2024
    risk 0.47cvss 7.2epss 0.00

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.

  • CVE-2024-29757HigApr 5, 2024
    risk 0.47cvss 7.3epss 0.00

    there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20034HigMar 4, 2024
    risk 0.47cvss 7.2epss 0.00

    In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849.

  • CVE-2023-45780HigOct 30, 2023
    risk 0.47cvss 7.3epss 0.00

    In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-35649HigOct 11, 2023
    risk 0.47cvss 7.2epss 0.00

    In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-33913HigAug 7, 2023
    risk 0.47cvss 7.2epss 0.01

    In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed

  • CVE-2023-35691HigJul 13, 2023
    risk 0.47cvss 7.2epss 0.00

    there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21251HigJul 13, 2023
    risk 0.47cvss 7.3epss 0.00

    In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-21189HigJun 28, 2023
    risk 0.47cvss 7.3epss 0.00

    In startLockTaskMode of LockTaskController.java, there is a possible bypass of lock task mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2023-21054HigMar 24, 2023
    risk 0.47cvss 7.2epss 0.01

    In EUTRAN_LCS_ConvertLCS_MOLRReq of LPP_CommonUtil.c, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-20976HigMar 24, 2023
    risk 0.47cvss 7.3epss 0.00

    In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-20921HigJan 26, 2023
    risk 0.47cvss 7.3epss 0.00

    In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2022-20603HigDec 16, 2022
    risk 0.47cvss 7.2epss 0.01

    In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20501HigDec 13, 2022
    risk 0.47cvss 7.3epss 0.00

    In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction…

  • CVE-2022-20442HigDec 13, 2022
    risk 0.47cvss 7.3epss 0.00

    In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is…

  • CVE-2022-30755HigJul 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

  • CVE-2022-20193HigJun 15, 2022
    risk 0.47cvss 7.3epss 0.00

    In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed. User interaction is…

Page 201 of 426