VYPR

Android

by Google

CVEs (8,504)

  • CVE-2021-25482MedOct 6, 2021
    risk 0.38cvss 5.9epss 0.00

    SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.

  • CVE-2021-25457MedSep 9, 2021
    risk 0.38cvss 5.9epss 0.00

    An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.

  • CVE-2021-25365MedApr 9, 2021
    risk 0.38cvss 5.9epss 0.00

    An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.

  • CVE-2019-9414MedSep 27, 2019
    risk 0.38cvss 5.9epss 0.01

    In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction…

  • CVE-2019-9399MedSep 27, 2019
    risk 0.38cvss 5.9epss 0.00

    The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:…

  • CVE-2018-5826MedApr 3, 2018
    risk 0.38cvss 5.9epss 0.00

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, due to a race condition, a Use After Free condition can occur in the WLAN driver.

  • CVE-2017-11063MedOct 10, 2017
    risk 0.38cvss 5.9epss 0.01

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, as a result of a race condition between two userspace processes that interact with the driver concurrently, a null pointer dereference can potentially occur.

  • CVE-2017-8242MedJun 13, 2017
    risk 0.38cvss 5.9epss 0.00

    In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.

  • CVE-2016-5341MedDec 6, 2016
    risk 0.38cvss 5.9epss 0.01

    The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 31470303 and…

  • CVE-2016-6709MedNov 25, 2016
    risk 0.38cvss 5.9epss 0.01

    An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is…

  • CVE-2016-0818MedMar 12, 2016
    risk 0.38cvss 5.9epss 0.00

    The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows…

  • CVE-2026-0165MedJun 16, 2026
    risk 0.37cvss 5.7epss 0.00

    In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-32330MedSep 4, 2025
    risk 0.37cvss 5.7epss 0.00

    In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User…

  • CVE-2017-13318MedJan 28, 2025
    risk 0.37cvss 5.7epss 0.00

    In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2017-13317MedJan 28, 2025
    risk 0.37cvss 5.7epss 0.00

    In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2022-39899MedDec 8, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

  • CVE-2022-26091MedApr 11, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.

  • CVE-2021-25501MedNov 5, 2021
    risk 0.37cvss 5.7epss 0.00

    An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

  • CVE-2020-0379MedSep 17, 2020
    risk 0.37cvss 5.7epss 0.00

    In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2018-9566MedDec 6, 2018
    risk 0.37cvss 5.7epss 0.00

    In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure when connecting to a malicious Bluetooth device with no additional execution privileges needed. User…

Page 285 of 426