VYPR

Android

by Google

CVEs (8,504)

  • CVE-2018-9482MedNov 20, 2024
    risk 0.42cvss 6.5epss 0.00

    In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9481MedNov 20, 2024
    risk 0.42cvss 6.5epss 0.00

    In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9480MedNov 20, 2024
    risk 0.42cvss 6.5epss 0.00

    In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2018-9440MedNov 19, 2024
    risk 0.42cvss 6.5epss 0.00

    In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2018-9371MedNov 19, 2024
    risk 0.42cvss 6.4epss 0.00

    In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with…

  • CVE-2018-9348MedNov 19, 2024
    risk 0.42cvss 6.5epss 0.00

    In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2017-13313MedNov 15, 2024
    risk 0.42cvss 6.5epss 0.00

    In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction…

  • CVE-2024-39438MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2024-39437MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2024-39436MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2024-39435MedSep 27, 2024
    risk 0.42cvss 6.5epss 0.00

    In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

  • CVE-2024-23709MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.01

    In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-25990MedMar 11, 2024
    risk 0.42cvss 6.4epss 0.00

    In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0045MedMar 11, 2024
    risk 0.42cvss 6.5epss 0.00

    In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0032MedFeb 16, 2024
    risk 0.42cvss 6.5epss 0.00

    In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-48420MedDec 8, 2023
    risk 0.42cvss 6.4epss 0.00

    there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40090MedDec 4, 2023
    risk 0.42cvss 6.5epss 0.01

    In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21395MedOct 30, 2023
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21315MedOct 30, 2023
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35645MedOct 11, 2023
    risk 0.42cvss 6.4epss 0.00

    In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Page 262 of 426