VYPR

Android

by Google

CVEs (8,504)

  • CVE-2017-13234MedFeb 12, 2018
    risk 0.42cvss 6.5epss 0.01

    In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1,…

  • CVE-2017-13233MedFeb 12, 2018
    risk 0.42cvss 6.5epss 0.01

    In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0,…

  • CVE-2017-13148MedDec 6, 2017
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65717533.

  • CVE-2017-0880MedDec 6, 2017
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID A-65646012.

  • CVE-2017-0874MedDec 6, 2017
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63315932.

  • CVE-2017-0873MedDec 6, 2017
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63316255.

  • CVE-2017-0783MedSep 14, 2017
    risk 0.42cvss 6.5epss 0.00

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.

  • CVE-2017-0792MedSep 8, 2017
    risk 0.42cvss 6.5epss 0.00

    A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.

  • CVE-2017-3750MedJun 29, 2017
    risk 0.42cvss 6.4epss 0.00

    On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.

  • CVE-2017-3749MedJun 29, 2017
    risk 0.42cvss 6.4epss 0.00

    On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.

  • CVE-2015-3830MedJun 6, 2017
    risk 0.42cvss 6.5epss 0.01

    The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.

  • CVE-2016-5348MedOct 10, 2016
    risk 0.42cvss 5.9epss 0.05

    The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or…

  • CVE-2016-3882MedOct 10, 2016
    risk 0.42cvss 6.5epss 0.00

    Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (reboot) via an access point that provides a crafted (1) Venue Group or (2) Venue Type value, aka…

  • CVE-2016-2411MedApr 18, 2016
    risk 0.42cvss 6.5epss 0.01

    A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053.

  • CVE-2016-0830MedMar 12, 2016
    risk 0.42cvss 6.5epss 0.01

    btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of configuration entries, and consequently exceeding the maximum size of a configuration…

  • CVE-2024-20055MedApr 1, 2024
    risk 0.41cvss 6.3epss 0.00

    In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

  • CVE-2023-20851MedSep 4, 2023
    risk 0.41cvss 6.3epss 0.00

    In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

  • CVE-2021-25511MedDec 8, 2021
    risk 0.41cvss 6.3epss 0.00

    An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

  • CVE-2016-2107MedMay 5, 2016
    risk 0.41cvss 5.9epss 0.89

    The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE:…

  • CVE-2026-0055MedJun 1, 2026
    risk 0.40cvss 6.2epss 0.00

    In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User…

Page 279 of 426