VYPR

Android

by Google

CVEs (8,504)

  • CVE-2024-0038HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2024-0036HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution…

  • CVE-2024-0035HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-0034HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0033HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0029HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-0014HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40115HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40114HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-40111HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed…

  • CVE-2023-40110HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-40109HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-40107HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40106HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-40100HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22012HigFeb 7, 2024
    risk 0.51cvss 7.8epss 0.00

    there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20015HigFeb 5, 2024
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419.

  • CVE-2023-48421HigDec 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution…

  • CVE-2023-48409HigDec 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2023-48407HigDec 8, 2023
    risk 0.51cvss 7.8epss 0.00

    there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Page 76 of 426