VYPR

Android

by Google

CVEs (8,504)

  • CVE-2021-0659MedNov 18, 2021
    risk 0.29cvss 4.4epss 0.00

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687559; Issue ID: ALPS05687559.

  • CVE-2021-0939MedOct 25, 2021
    risk 0.29cvss 4.4epss 0.00

    In set_default_passthru_cfg of passthru.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-25480MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.

  • CVE-2021-25477MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.01

    An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.

  • CVE-2021-25474MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

  • CVE-2021-25473MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

  • CVE-2021-25468MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.

  • CVE-2021-25450MedSep 9, 2021
    risk 0.29cvss 4.5epss 0.00

    Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.

  • CVE-2021-0590MedJul 14, 2021
    risk 0.29cvss 4.4epss 0.00

    In sendNetworkConditionsBroadcast of NetworkMonitor.java, there is a possible way for a privileged app to receive WiFi BSSID and SSID without location permissions due to a missing permission check. This could lead to local information disclosure with System execution privileges…

  • CVE-2021-0605MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0549MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-0541MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-0566MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-25411MedJun 11, 2021
    risk 0.29cvss 4.4epss 0.00

    Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.

  • CVE-2021-0460MedMar 10, 2021
    risk 0.29cvss 4.4epss 0.00

    In the FingerTipS touch screen driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0459MedMar 10, 2021
    risk 0.29cvss 4.4epss 0.00

    In fts_driver_test_write of fts_proc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0458MedMar 10, 2021
    risk 0.29cvss 4.4epss 0.00

    In the FingerTipS touch screen driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0453MedMar 10, 2021
    risk 0.29cvss 4.4epss 0.00

    In the Titan-M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0452MedMar 10, 2021
    risk 0.29cvss 4.4epss 0.00

    In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0451MedMar 10, 2021
    risk 0.29cvss 4.4epss 0.00

    In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

Page 394 of 426