VYPR

Android

by Google

CVEs (8,504)

  • CVE-2020-0356MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0336MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444

  • CVE-2020-0330MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0431MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2020-0429MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0403MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product:…

  • CVE-2020-25280MedSep 11, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated attackers can execute LTE/5G commands by sending a debugging command over USB. The Samsung ID is SVE-2020-16979 (September 2020).

  • CVE-2020-0256MedAug 11, 2020
    risk 0.44cvss 6.8epss 0.00

    In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0122MedJul 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed…

  • CVE-2020-0186MedJun 11, 2020
    risk 0.44cvss 6.7epss 0.00

    In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0165MedJun 11, 2020
    risk 0.44cvss 6.7epss 0.00

    In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege via compromised device firmware with System execution privileges needed. User interaction is not…

  • CVE-2020-0153MedJun 11, 2020
    risk 0.44cvss 6.7epss 0.00

    In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0124MedJun 11, 2020
    risk 0.44cvss 6.7epss 0.00

    In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0220MedMay 14, 2020
    risk 0.44cvss 6.7epss 0.00

    In crus_afe_callback of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0076MedApr 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In get_auth_result of the FPC IRIS TrustZone app, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-20785MedApr 17, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January 2019).

  • CVE-2018-21061MedApr 8, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical functions in the locked state. The Samsung ID is SVE-2016-6341 (August 2018).

  • CVE-2019-20594MedMar 24, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software. A heap overflow exists in the bootloader. The Samsung ID is SVE-2019-14371 (July 2019).

  • CVE-2020-10847MedMar 24, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).

  • CVE-2020-10839MedMar 24, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).

Page 255 of 426