VYPR

Android

by Google

CVEs (8,504)

  • CVE-2020-0469MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0468MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2020-0467MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to local information disclosure of secure network traffic over a non-VPN link with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0464MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0454MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of the current SSID with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-0453MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0448MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an account across devices, with no…

  • CVE-2020-0443MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0437MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-0424MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In send_vc of res_send.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0419MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2020-0415MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0410MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0…

  • CVE-2020-0400MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0398MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2020-0378MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…

  • CVE-2020-0246MedOct 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0365MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137346580

  • CVE-2020-0331MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147309310

  • CVE-2020-0327MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129151407

Page 337 of 426