VYPR

Android

by Google

CVEs (8,504)

  • CVE-2023-21274MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21271MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21234MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-21230MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information disclosure with no…

  • CVE-2023-21268MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21267MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2023-33912MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-33911MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-33910MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-33909MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-33908MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-33907MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-33906MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • CVE-2023-21260MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.

  • CVE-2023-21249MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21243MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed…

  • CVE-2023-21240MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21239MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21238MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-20942MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

Page 305 of 426