VYPR

Vendor CVEs

Google

All CVEs

16,116 total · sorted by risk
  • CVE-2018-9340MedNov 19, 2024
    risk 0.36cvss 5.5epss 0.00

    In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.

  • CVE-2017-13309MedNov 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2017-13227MedNov 14, 2024
    risk 0.36cvss 5.5epss 0.00

    In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.

  • CVE-2024-43086MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2024-43084MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43083MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43082MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47034MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47029MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2024-47026MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47025MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47019MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

  • CVE-2024-47018MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47015MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for…

  • CVE-2024-44099MedOct 25, 2024
    risk 0.36cvss 5.5epss 0.00

    There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-40659MedSep 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service…

  • CVE-2024-40656MedSep 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2024-34742MedAug 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-34721MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.00

    In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-31314MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-31312MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32930MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32926MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32914MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32912MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    there is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of service of impaired use of the device with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32910MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-32893MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29785MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29780MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2024-23712MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed…

  • CVE-2024-0027MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0026MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0022MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2024-3838MedApr 17, 2024
    risk 0.36cvss 5.5epss 0.00

    Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)

  • CVE-2023-52352MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.00

    In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-52347MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.00

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-52343MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.00

    In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2024-29782MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29751MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29750MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29744MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29742MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29739MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29738MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27232MedApr 5, 2024
    risk 0.36cvss 5.5epss 0.00

    In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27237MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27235MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27218MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22010MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0047MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction…

Page 207 of 323