VYPR

Android

by Google

CVEs (8,504)

  • CVE-2021-0409MedOct 25, 2021
    risk 0.36cvss 5.5epss 0.00

    In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561359; Issue ID:…

  • CVE-2021-0706MedOct 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0702MedOct 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore downgrade. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0651MedOct 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0643MedOct 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User…

  • CVE-2021-25488MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.

  • CVE-2021-0695MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0693MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0689MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0686MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2021-0682MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-0681MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0680MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0644MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed…

  • CVE-2021-0425MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05400059.

  • CVE-2021-0424MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05393787.

  • CVE-2021-0423MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID:…

  • CVE-2021-0422MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381071.

  • CVE-2021-0421MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue…

  • CVE-2021-25456MedSep 9, 2021
    risk 0.36cvss 5.5epss 0.00

    OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.

Page 332 of 426