VYPR

Android

by Google

CVEs (8,504)

  • CVE-2024-27237MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27235MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27218MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22010MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0047MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction…

  • CVE-2024-0020MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed.…

  • CVE-2024-0017MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-40085MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0030MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40093MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40124MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40113MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40112MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. User interaction is not needed…

  • CVE-2023-40105MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-48354MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-48352MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48351MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48350MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48349MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-48348MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

Page 293 of 426