VYPR

Android

by Google

CVEs (4,716)

  • CVE-2019-2195HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-2193HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Admin app installed with no indication to the user, with User execution privileges…

  • CVE-2019-2192HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2019-2173HigOct 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-2114HigOct 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an application with no additional execution privileges needed.…

  • CVE-2019-2131HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1…

  • CVE-2019-2017HigJun 19, 2019
    risk 0.51cvss 7.8epss 0.00

    In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2019-2011HigJun 19, 2019
    risk 0.51cvss 7.8epss 0.00

    In readNullableNativeHandleNoDup of Parcel.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-1985HigJun 19, 2019
    risk 0.51cvss 7.8epss 0.00

    In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2019-2092HigJun 7, 2019
    risk 0.51cvss 7.8epss 0.00

    In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is not needed for…

  • CVE-2019-2091HigJun 7, 2019
    risk 0.51cvss 7.8epss 0.00

    In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is not needed for…

  • CVE-2019-2049HigMay 8, 2019
    risk 0.51cvss 7.8epss 0.00

    In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed…

  • CVE-2019-2034HigApr 19, 2019
    risk 0.51cvss 7.8epss 0.00

    In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the NFC process with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2019-2026HigApr 19, 2019
    risk 0.51cvss 7.8epss 0.00

    In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local escalation of privilege and FRP bypass with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2018-9582HigFeb 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In package installer in Android-8.0, Android-8.1 and Android-9, there is a possible bypass of the unknown source warning due to a confused deputy scenario. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2018-9577HigDec 7, 2018
    risk 0.51cvss 7.8epss 0.01

    In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.…

  • CVE-2018-9576HigDec 7, 2018
    risk 0.51cvss 7.8epss 0.01

    In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.…

  • CVE-2018-9575HigDec 7, 2018
    risk 0.51cvss 7.8epss 0.01

    In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2018-9574HigDec 7, 2018
    risk 0.51cvss 7.8epss 0.01

    In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product:…

  • CVE-2018-9573HigDec 7, 2018
    risk 0.51cvss 7.8epss 0.01

    In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android.…

Page 68 of 236