VYPR

Android

by Google

CVEs (8,504)

  • CVE-2021-25461MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

  • CVE-2021-25460MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.

  • CVE-2021-25459MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.

  • CVE-2021-25392MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.

  • CVE-2021-25391MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

  • CVE-2021-25390MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

  • CVE-2021-25364MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.

  • CVE-2021-25359MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.

  • CVE-2021-25358MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.

  • CVE-2021-25345MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.

  • CVE-2016-3764MedJul 11, 2016
    risk 0.26cvss 4.0epss 0.00

    media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive pointer information via a crafted application, aka internal bug 28377502.

  • CVE-2016-3761MedJul 11, 2016
    risk 0.26cvss 4.0epss 0.00

    NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.

  • CVE-2025-20643LowFeb 3, 2025
    risk 0.25cvss 3.9epss 0.00

    In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for…

  • CVE-2022-20226LowJul 13, 2022
    risk 0.25cvss 3.9epss 0.00

    In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-24001LowFeb 11, 2022
    risk 0.25cvss 3.8epss 0.00

    Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.

  • CVE-2022-24000LowFeb 11, 2022
    risk 0.25cvss 3.9epss 0.00

    PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

  • CVE-2022-23999LowFeb 11, 2022
    risk 0.25cvss 3.9epss 0.00

    PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

  • CVE-2022-23427LowFeb 11, 2022
    risk 0.25cvss 3.9epss 0.00

    PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.

  • CVE-2021-25475LowOct 6, 2021
    risk 0.25cvss 3.9epss 0.00

    A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25471LowOct 6, 2021
    risk 0.24cvss 3.7epss 0.00

    A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.

Page 405 of 426