VYPR

Android

by Google

CVEs (8,504)

  • CVE-2019-9236MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122322613

  • CVE-2019-9235MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122323053

  • CVE-2019-2040MedApr 19, 2019
    risk 0.33cvss 5.0epss 0.00

    In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android.…

  • CVE-2019-2039MedApr 19, 2019
    risk 0.33cvss 5.0epss 0.00

    In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions:…

  • CVE-2018-9438MedNov 6, 2018
    risk 0.33cvss 5.0epss 0.00

    When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is needed for exploitation.…

  • CVE-2015-8956MedOct 10, 2016
    risk 0.33cvss 6.1epss 0.00

    The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket.

  • CVE-2015-6645MedJan 6, 2016
    risk 0.33cvss 5.0epss 0.01

    SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.

  • CVE-2024-20102MedOct 7, 2024
    risk 0.32cvss 4.9epss 0.00

    In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; Issue ID: MSV-1601.

  • CVE-2023-48413MedDec 8, 2023
    risk 0.32cvss 4.9epss 0.00

    In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-48397MedDec 8, 2023
    risk 0.32cvss 4.9epss 0.00

    In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-20606MedDec 16, 2022
    risk 0.32cvss 4.9epss 0.01

    In SAEMM_MiningCodecTableWithMsgIE of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2022-39847MedOct 7, 2022
    risk 0.32cvss 4.9epss 0.00

    Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2022-36849MedSep 9, 2022
    risk 0.32cvss 4.9epss 0.00

    Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2022-36847MedSep 9, 2022
    risk 0.32cvss 4.9epss 0.00

    Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2021-0660MedSep 27, 2021
    risk 0.32cvss 4.9epss 0.00

    In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827145; Issue ID: ALPS05827145.

  • CVE-2020-0348MedSep 18, 2020
    risk 0.32cvss 4.9epss 0.01

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0157MedJun 11, 2020
    risk 0.32cvss 4.9epss 0.01

    In nfa_hci_conn_cback of nfa_hci_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for…

  • CVE-2019-9434MedSep 27, 2019
    risk 0.32cvss 4.9epss 0.01

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2019-9431MedSep 27, 2019
    risk 0.32cvss 4.9epss 0.01

    In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2016-5696MedAug 6, 2016
    risk 0.32cvss 4.8epss 0.15

    net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

Page 369 of 426