VYPR

Android

by Google

CVEs (8,504)

  • CVE-2026-20437MedMar 2, 2026
    risk 0.29cvss 4.4epss 0.00

    In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431940; Issue ID: MSV-5843.

  • CVE-2026-20429MedMar 2, 2026
    risk 0.29cvss 4.4epss 0.00

    In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID:…

  • CVE-2026-20424MedMar 2, 2026
    risk 0.29cvss 4.4epss 0.00

    In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID:…

  • CVE-2025-20789MedDec 2, 2025
    risk 0.29cvss 4.4epss 0.00

    In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS10117741; Issue ID: MSV-4538.

  • CVE-2025-20788MedDec 2, 2025
    risk 0.29cvss 4.4epss 0.00

    In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS10117735; Issue ID: MSV-4539.

  • CVE-2025-26427MedSep 4, 2025
    risk 0.29cvss 4.4epss 0.00

    In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-26420MedSep 4, 2025
    risk 0.29cvss 4.4epss 0.00

    In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2018-9384MedJan 17, 2025
    risk 0.29cvss 4.4epss 0.00

    In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9383MedJan 17, 2025
    risk 0.29cvss 4.4epss 0.00

    In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20152MedJan 6, 2025
    risk 0.29cvss 4.4epss 0.00

    In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 /…

  • CVE-2018-9408MedDec 5, 2024
    risk 0.29cvss 4.4epss 0.00

    In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20116MedDec 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.

  • CVE-2024-20124MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1568.

  • CVE-2024-20123MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1569.

  • CVE-2024-20122MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1572.

  • CVE-2024-20117MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1681.

  • CVE-2024-20112MedNov 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.

  • CVE-2024-47028MedOct 25, 2024
    risk 0.29cvss 4.4epss 0.00

    In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20097MedOct 7, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1630.

  • CVE-2024-20096MedOct 7, 2024
    risk 0.29cvss 4.4epss 0.00

    In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996900; Issue ID: MSV-1635.

Page 376 of 426