VYPR

Android

by Google

CVEs (8,504)

  • CVE-2025-48572HigKEVDec 8, 2025
    risk 0.63cvss 7.8epss 0.00

    In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32896HigKEVJun 13, 2024
    risk 0.63cvss 7.8epss 0.03

    there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-29748HigKEVApr 5, 2024
    risk 0.63cvss 7.8epss 0.01

    there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-35674HigKEVSep 11, 2023
    risk 0.63cvss 7.8epss 0.02

    In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-20963HigKEVMar 24, 2023
    risk 0.63cvss 7.8epss 0.01

    In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID:…

  • CVE-2021-39793HigKEVMar 16, 2022
    risk 0.63cvss 7.8epss 0.01

    In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1048HigKEVDec 15, 2021
    risk 0.63cvss 7.8epss 0.01

    In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0069HigKEVMar 10, 2020
    risk 0.63cvss 7.8epss 0.01

    In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2020-0041HigKEVMar 10, 2020
    risk 0.63cvss 7.8epss 0.03

    In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2016-2108CriMay 5, 2016
    risk 0.63cvss 9.8epss 0.78

    The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.

  • CVE-2017-0781HigSep 14, 2017
    risk 0.62cvss 8.8epss 0.23

    A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

  • CVE-2019-2107HigJul 8, 2019
    risk 0.61cvss 8.8epss 0.09

    In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions:…

  • CVE-2016-6754HigNov 25, 2016
    risk 0.61cvss 8.8epss 0.05

    A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of…

  • CVE-2026-0106CriFeb 5, 2026
    risk 0.60cvss 9.3epss 0.00

    In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43093HigKEVNov 13, 2024
    risk 0.60cvss 7.3epss 0.01

    In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution…

  • CVE-2019-20606CriMar 24, 2020
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered on Samsung mobile devices with any (before May 2019) software. A phishing attack against OMACP can change the network and internet settings. The Samsung ID is SVE-2019-14073 (May 2019).

  • CVE-2025-48609CriMar 2, 2026
    risk 0.59cvss 9.1epss 0.00

    In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User…

  • CVE-2024-27207CriMar 11, 2024
    risk 0.59cvss 9.1epss 0.00

    Exported broadcast receivers allowing malicious apps to bypass broadcast protection.

  • CVE-2021-39635CriFeb 11, 2022
    risk 0.59cvss 9.1epss 0.01

    ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2021-25387CriJun 11, 2021
    risk 0.59cvss 9.0epss 0.01

    An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

Page 34 of 426