VYPR

Android

by Google

CVEs (8,504)

  • CVE-2023-44128MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the…

  • CVE-2023-44121MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action…

  • CVE-2023-21190MedJun 28, 2023
    risk 0.33cvss 5.0epss 0.00

    In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2023-21090MedApr 19, 2023
    risk 0.33cvss 5.0epss 0.00

    In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20521MedDec 16, 2022
    risk 0.33cvss 5.0epss 0.00

    In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20394MedOct 11, 2022
    risk 0.33cvss 5.0epss 0.00

    In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-39855MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

  • CVE-2022-36848MedSep 9, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

  • CVE-2022-20266MedAug 12, 2022
    risk 0.33cvss 5.0epss 0.00

    In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2022-33731MedAug 5, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

  • CVE-2022-33695MedJul 12, 2022
    risk 0.33cvss 5.1epss 0.00

    Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

  • CVE-2022-20196MedJun 15, 2022
    risk 0.33cvss 5.0epss 0.00

    In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID:…

  • CVE-2022-20195MedJun 15, 2022
    risk 0.33cvss 5.0epss 0.00

    In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-28780MedMay 3, 2022
    risk 0.33cvss 5.0epss 0.00

    Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

  • CVE-2021-1023MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2021-0973MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0952MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-0919MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-25503MedNov 5, 2021
    risk 0.33cvss 5.0epss 0.00

    Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

  • CVE-2021-0687MedOct 6, 2021
    risk 0.33cvss 5.0epss 0.00

    In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11…

Page 367 of 426