VYPR

Android

by Google

CVEs (8,504)

  • CVE-2017-0709LowJul 6, 2017
    risk 0.21cvss 3.3epss 0.00

    A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.

  • CVE-2015-9032LowJun 13, 2017
    risk 0.21cvss 3.3epss 0.00

    In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.

  • CVE-2015-9031LowJun 13, 2017
    risk 0.21cvss 3.3epss 0.00

    In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.

  • CVE-2016-6770LowJan 12, 2017
    risk 0.21cvss 3.3epss 0.00

    An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android.…

  • CVE-2016-3763LowJul 11, 2016
    risk 0.21cvss 3.3epss 0.01

    net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to…

  • CVE-2016-3759LowJul 11, 2016
    risk 0.21cvss 3.3epss 0.00

    The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.

  • CVE-2023-21262LowJul 13, 2023
    risk 0.20cvss 3.1epss 0.00

    In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.

  • CVE-2021-25454LowSep 9, 2021
    risk 0.20cvss 3.1epss 0.00

    OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

  • CVE-2015-6641LowJan 6, 2016
    risk 0.20cvss 3.1epss 0.00

    Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.

  • CVE-2026-0121LowMar 10, 2026
    risk 0.19cvss 2.9epss 0.00

    In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2022-27834LowApr 11, 2022
    risk 0.19cvss 2.9epss 0.00

    Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2022-27831LowApr 11, 2022
    risk 0.19cvss 2.9epss 0.00

    Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.

  • CVE-2016-0823MedMar 12, 2016
    risk 0.19cvss 4.0epss 0.00

    The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.

  • CVE-2022-20327LowAug 12, 2022
    risk 0.18cvss 2.8epss 0.00

    In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-25336LowMar 4, 2021
    risk 0.18cvss 2.8epss 0.00

    Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.

  • CVE-2022-20529LowDec 16, 2022
    risk 0.16cvss 2.4epss 0.00

    In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20245LowAug 11, 2022
    risk 0.16cvss 2.4epss 0.00

    In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-33720LowAug 5, 2022
    risk 0.16cvss 2.4epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.

  • CVE-2022-30721LowJun 7, 2022
    risk 0.16cvss 2.5epss 0.00

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

  • CVE-2022-30720LowJun 7, 2022
    risk 0.16cvss 2.5epss 0.00

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Page 414 of 426