VYPR

Android

by Google

CVEs (8,504)

  • CVE-2022-20216CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.01

    android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916

  • CVE-2022-20210CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.04

    The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which…

  • CVE-2022-20191CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A

  • CVE-2022-20173CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

  • CVE-2022-20171CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A

  • CVE-2022-20170CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A

  • CVE-2022-20167CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

  • CVE-2022-20164CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A

  • CVE-2022-20160CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A

  • CVE-2022-20145CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.07

    In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is…

  • CVE-2022-20140CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.09

    In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20130CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.09

    In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20127CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.07

    In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2022-20120CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A

  • CVE-2021-39737CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A

  • CVE-2021-39723CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A

  • CVE-2021-39720CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A

  • CVE-2021-39710CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A

  • CVE-2021-39708CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39675CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.06

    In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

Page 8 of 426