VYPR

Android

by Google

CVEs (8,504)

  • CVE-2022-20114HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2022-20113HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20005HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-20004HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-21743HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: ALPS06371108.

  • CVE-2022-20109HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399915.

  • CVE-2022-20099HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296442.

  • CVE-2022-20093HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498868;…

  • CVE-2022-20088HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.

  • CVE-2022-20084HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-39812HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:…

  • CVE-2021-39808HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2021-39807HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User…

  • CVE-2021-39802HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39801HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-39799HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39798HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39797HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39794HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0707HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

Page 98 of 426