VYPR

Android

by Google

CVEs (8,504)

  • CVE-2024-27225MedMar 11, 2024
    risk 0.29cvss 4.4epss 0.00

    In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20036MedMar 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.

  • CVE-2024-20033MedMar 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08499945; Issue ID: ALPS08499945.

  • CVE-2024-20030MedMar 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741.

  • CVE-2024-20020MedMar 4, 2024
    risk 0.29cvss 4.4epss 0.00

    In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.

  • CVE-2024-20016MedFeb 5, 2024
    risk 0.29cvss 4.4epss 0.00

    In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.

  • CVE-2023-48359MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48358MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48357MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48356MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48355MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48353MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48342MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-48339MedJan 18, 2024
    risk 0.29cvss 4.4epss 0.00

    In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

  • CVE-2023-32881MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308080.

  • CVE-2023-32880MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.

  • CVE-2023-32878MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.

  • CVE-2023-32876MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612.

  • CVE-2023-32875MedJan 2, 2024
    risk 0.29cvss 4.4epss 0.00

    In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217.

  • CVE-2023-32858MedDec 4, 2023
    risk 0.29cvss 4.4epss 0.00

    In GZ, there is a possible information disclosure due to a missing data erasing. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07806008; Issue ID: ALPS07806008.

Page 378 of 426