VYPR

Android

by Google

CVEs (8,504)

  • CVE-2025-20765MedDec 2, 2025
    risk 0.31cvss 4.7epss 0.00

    In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833.

  • CVE-2024-32904MedJun 13, 2024
    risk 0.31cvss 4.7epss 0.00

    In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

  • CVE-2024-32898MedJun 13, 2024
    risk 0.31cvss 4.7epss 0.00

    In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

  • CVE-2024-29778MedJun 13, 2024
    risk 0.31cvss 4.7epss 0.00

    In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2023-21095MedJun 15, 2023
    risk 0.31cvss 4.7epss 0.00

    In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21031MedMar 24, 2023
    risk 0.31cvss 4.7epss 0.00

    In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-47331MedFeb 12, 2023
    risk 0.31cvss 4.7epss 0.00

    In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.

  • CVE-2022-20214MedJan 26, 2023
    risk 0.31cvss 4.7epss 0.00

    In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID:…

  • CVE-2022-42771MedDec 6, 2022
    risk 0.31cvss 4.7epss 0.00

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

  • CVE-2022-42770MedDec 6, 2022
    risk 0.31cvss 4.7epss 0.00

    In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

  • CVE-2022-39134MedDec 6, 2022
    risk 0.31cvss 4.7epss 0.00

    In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.

  • CVE-2022-33727MedAug 5, 2022
    risk 0.31cvss 4.8epss 0.00

    A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

  • CVE-2022-33723MedAug 5, 2022
    risk 0.31cvss 4.8epss 0.00

    A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

  • CVE-2022-20097MedMay 3, 2022
    risk 0.31cvss 4.7epss 0.00

    In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06383944.

  • CVE-2021-0443MedApr 13, 2021
    risk 0.31cvss 4.7epss 0.00

    In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is…

  • CVE-2021-0320MedJan 11, 2021
    risk 0.31cvss 4.7epss 0.00

    In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2020-0373MedSep 17, 2020
    risk 0.31cvss 4.7epss 0.00

    In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android…

  • CVE-2015-9546MedApr 10, 2020
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences…

  • CVE-2020-0008MedJan 8, 2020
    risk 0.31cvss 4.7epss 0.00

    In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.…

  • CVE-2019-2219MedDec 6, 2019
    risk 0.31cvss 4.7epss 0.00

    In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges…

Page 370 of 426