VYPR

Android

by Google

CVEs (8,504)

  • CVE-2024-32915MedJun 13, 2024
    risk 0.28cvss 4.3epss 0.00

    In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.

  • CVE-2023-21419MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

  • CVE-2022-42768MedDec 6, 2022
    risk 0.28cvss 4.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-39887MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

  • CVE-2022-39884MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

  • CVE-2021-25430MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

  • CVE-2021-25429MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

  • CVE-2020-0499MedDec 15, 2020
    risk 0.28cvss 4.3epss 0.04

    In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2017-18667MedApr 7, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can prevent users from learning that SMS storage space has been exhausted. The Samsung ID is SVE-2017-8702 (June 2017).

  • CVE-2017-18653MedApr 7, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. The Email application allows attackers to send emails on behalf of any user via a broadcasted intent. The Samsung ID is SVE-2017-9357 (September 2017).

  • CVE-2020-0052MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.00

    In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for…

  • CVE-2019-2191MedSep 27, 2019
    risk 0.28cvss 4.3epss 0.00

    In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required for exploitation.Product:…

  • CVE-2019-2190MedSep 27, 2019
    risk 0.28cvss 4.3epss 0.00

    In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required for exploitation.Product:…

  • CVE-2017-13269MedApr 4, 2018
    risk 0.28cvss 4.3epss 0.00

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68818034.

  • CVE-2017-13268MedApr 4, 2018
    risk 0.28cvss 4.3epss 0.00

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67058064.

  • CVE-2015-5310MedJan 6, 2016
    risk 0.28cvss 4.3epss 0.01

    The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service…

  • CVE-2025-20745MedNov 4, 2025
    risk 0.27cvss 4.2epss 0.00

    In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10095441; Issue ID: MSV-4294.

  • CVE-2025-20744MedNov 4, 2025
    risk 0.27cvss 4.2epss 0.00

    In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10127160; Issue ID: MSV-4542.

  • CVE-2025-20743MedNov 4, 2025
    risk 0.27cvss 4.2epss 0.00

    In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10136671; Issue ID:…

  • CVE-2025-20651MedMar 3, 2025
    risk 0.27cvss 4.1epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:…

Page 399 of 426