Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27225 | Med | 0.29 | 4.4 | 0.00 | Mar 11, 2024 | In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-20036 | Med | 0.29 | 4.4 | 0.00 | Mar 4, 2024 | In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508. | ||
| CVE-2024-20033 | Med | 0.29 | 4.4 | 0.00 | Mar 4, 2024 | In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08499945; Issue ID: ALPS08499945. | ||
| CVE-2024-20030 | Med | 0.29 | 4.4 | 0.00 | Mar 4, 2024 | In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741. | ||
| CVE-2024-20020 | Med | 0.29 | 4.4 | 0.00 | Mar 4, 2024 | In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504. | ||
| CVE-2024-20016 | Med | 0.29 | 4.4 | 0.00 | Feb 5, 2024 | In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901. | ||
| CVE-2023-48359 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48358 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48357 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48356 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48355 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48353 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48342 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-48339 | Med | 0.29 | 4.4 | 0.00 | Jan 18, 2024 | In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed | ||
| CVE-2023-32881 | Med | 0.29 | 4.4 | 0.00 | Jan 2, 2024 | In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308080. | ||
| CVE-2023-32880 | Med | 0.29 | 4.4 | 0.00 | Jan 2, 2024 | In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076. | ||
| CVE-2023-32878 | Med | 0.29 | 4.4 | 0.00 | Jan 2, 2024 | In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992. | ||
| CVE-2023-32876 | Med | 0.29 | 4.4 | 0.00 | Jan 2, 2024 | In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612. | ||
| CVE-2023-32875 | Med | 0.29 | 4.4 | 0.00 | Jan 2, 2024 | In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217. | ||
| CVE-2023-32858 | Med | 0.29 | 4.4 | 0.00 | Dec 4, 2023 | In GZ, there is a possible information disclosure due to a missing data erasing. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07806008; Issue ID: ALPS07806008. |
- risk 0.29cvss 4.4epss 0.00
In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
- risk 0.29cvss 4.4epss 0.00
In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.
- risk 0.29cvss 4.4epss 0.00
In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08499945; Issue ID: ALPS08499945.
- risk 0.29cvss 4.4epss 0.00
In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741.
- risk 0.29cvss 4.4epss 0.00
In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.
- risk 0.29cvss 4.4epss 0.00
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.
- risk 0.29cvss 4.4epss 0.00
In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
- risk 0.29cvss 4.4epss 0.00
In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308080.
- risk 0.29cvss 4.4epss 0.00
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.
- risk 0.29cvss 4.4epss 0.00
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.
- risk 0.29cvss 4.4epss 0.00
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612.
- risk 0.29cvss 4.4epss 0.00
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217.
- risk 0.29cvss 4.4epss 0.00
In GZ, there is a possible information disclosure due to a missing data erasing. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07806008; Issue ID: ALPS07806008.
Page 378 of 426