VYPR

Android

by Google

CVEs (8,504)

  • CVE-2019-9283MedSep 27, 2019
    risk 0.35cvss 6.5epss 0.01

    In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2016-0824MedMar 12, 2016
    risk 0.35cvss 5.3epss 0.01

    libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal…

  • CVE-2016-1940MedJan 31, 2016
    risk 0.35cvss 5.3epss 0.01

    Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.

  • CVE-2026-13030MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-20417MedFeb 2, 2026
    risk 0.34cvss 5.3epss 0.00

    In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10314946 /…

  • CVE-2025-36909MedSep 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Information disclosure

  • CVE-2025-20655MedApr 7, 2025
    risk 0.34cvss 5.3epss 0.00

    In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID:…

  • CVE-2024-20147MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.00

    In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX…

  • CVE-2024-40674MedJan 28, 2025
    risk 0.34cvss 5.3epss 0.00

    In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-34663MedOct 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2023-32871MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.

  • CVE-2023-52533MedApr 8, 2024
    risk 0.34cvss 5.3epss 0.00

    In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2023-52344MedApr 8, 2024
    risk 0.34cvss 5.3epss 0.00

    In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2024-22006MedMar 11, 2024
    risk 0.34cvss 5.3epss 0.00

    OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.

  • CVE-2024-0016MedFeb 16, 2024
    risk 0.34cvss 5.3epss 0.00

    In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-20530MedDec 16, 2022
    risk 0.34cvss 5.3epss 0.00

    In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-33715MedAug 5, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.

  • CVE-2022-26090MedApr 11, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.

  • CVE-2022-25819MedMar 10, 2022
    risk 0.34cvss 5.3epss 0.00

    OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.

  • CVE-2022-23429MedFeb 11, 2022
    risk 0.34cvss 5.3epss 0.00

    An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.

Page 362 of 426