VYPR

Android

by Google

CVEs (8,504)

  • CVE-2024-32918MedJun 13, 2024
    risk 0.40cvss 6.1epss 0.00

    Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps

  • CVE-2024-29754MedApr 5, 2024
    risk 0.40cvss 6.2epss 0.00

    In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20048MedApr 1, 2024
    risk 0.40cvss 6.2epss 0.00

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.

  • CVE-2024-25984MedMar 11, 2024
    risk 0.40cvss 6.2epss 0.00

    In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22007MedMar 11, 2024
    risk 0.40cvss 6.2epss 0.00

    In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-44125MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app…

  • CVE-2023-44124MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents…

  • CVE-2023-44123MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if it had access to app…

  • CVE-2023-44122MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents…

  • CVE-2022-39912MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

  • CVE-2022-33732MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.

  • CVE-2022-33718MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

  • CVE-2022-33714MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

  • CVE-2022-33702MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.

  • CVE-2022-33691MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.

  • CVE-2022-33689MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

  • CVE-2022-30727MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

  • CVE-2022-30726MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

  • CVE-2022-30722MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

  • CVE-2022-28783MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

Page 281 of 426