VYPR

Android

by Google

CVEs (8,504)

  • CVE-2022-23728MedJan 21, 2022
    risk 0.40cvss 6.1epss 0.00

    Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.

  • CVE-2022-22268MedJan 10, 2022
    risk 0.40cvss 6.1epss 0.00

    Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.

  • CVE-2021-25512MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.00

    An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

  • CVE-2021-25382MedApr 23, 2021
    risk 0.40cvss 6.1epss 0.00

    An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.

  • CVE-2021-25344MedMar 4, 2021
    risk 0.40cvss 6.2epss 0.00

    Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.

  • CVE-2018-21068MedApr 8, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a password via a split screen. The Samsung ID is SVE-2018-11669 (July 2018).

  • CVE-2018-21048MedApr 8, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device in Standalone Dex mode. The Samsung ID is SVE-2018-12925 (November 2018).

  • CVE-2018-21045MedApr 8, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lockscreen state via a copy-and-paste action. The Samsung ID is SVE-2018-13381 (December 2018).

  • CVE-2019-20569MedMar 24, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via the status bar. The Samsung ID is SVE-2019-15089 (September 2019).

  • CVE-2019-20554MedMar 24, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. Attackers can bypass Factory Reset Protection (FRP) via an external keyboard. The Samsung ID is SVE-2019-15164 (October 2019).

  • CVE-2019-20535MedMar 24, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devices can be established from the lock screen. The Samsung ID is SVE-2019-15533 (December 2019).

  • CVE-2017-13290MedApr 4, 2018
    risk 0.40cvss 6.2epss 0.00

    In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.…

  • CVE-2016-10398MedJul 17, 2017
    risk 0.40cvss 6.2epss 0.00

    Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured…

  • CVE-2015-8955HigOct 10, 2016
    risk 0.40cvss 7.3epss 0.00

    arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.

  • CVE-2016-2423MedApr 18, 2016
    risk 0.40cvss 6.1epss 0.00

    server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset…

  • CVE-2016-2421MedApr 18, 2016
    risk 0.40cvss 6.1epss 0.00

    Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.

  • CVE-2016-2414MedApr 18, 2016
    risk 0.40cvss 6.2epss 0.00

    The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka…

  • CVE-2016-0832MedMar 12, 2016
    risk 0.40cvss 6.1epss 0.00

    Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.

  • CVE-2016-0813MedFeb 7, 2016
    risk 0.40cvss 6.1epss 0.00

    packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before 2016-02-01 does not properly check for device provisioning, which allows physically proximate attackers to bypass the Factory…

  • CVE-2016-0812MedFeb 7, 2016
    risk 0.40cvss 6.1epss 0.00

    The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows physically proximate…

Page 282 of 426