Vendor CVEs
All CVEs
16,116 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0020 | Med | 0.36 | 5.5 | 0.00 | Feb 16, 2024 | In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed.… | ||
| CVE-2024-0017 | Med | 0.36 | 5.5 | 0.00 | Feb 16, 2024 | In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. | ||
| CVE-2023-40085 | Med | 0.36 | 5.5 | 0.00 | Feb 16, 2024 | In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-0030 | Med | 0.36 | 5.5 | 0.00 | Feb 16, 2024 | In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40093 | Med | 0.36 | 5.5 | 0.00 | Feb 16, 2024 | In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40124 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2024 | In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40113 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2024 | In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40112 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2024 | In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2023-40105 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2024 | In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-48354 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-48352 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48351 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48350 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48349 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48348 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48347 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48346 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48345 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48344 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48343 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48341 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48340 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-48422 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-48415 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-48412 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-48411 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for… | ||
| CVE-2023-48408 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation. | ||
| CVE-2023-48401 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-48399 | Med | 0.36 | 5.5 | 0.00 | Dec 8, 2023 | In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation. | ||
| CVE-2023-45781 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40098 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-40092 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40083 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40081 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-40076 | Med | 0.36 | 5.5 | 0.02 | Dec 4, 2023 | In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-40075 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is… | ||
| CVE-2023-40074 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40073 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-35668 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-42749 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42744 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42742 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42741 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42737 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42734 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42733 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42732 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42730 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42728 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42723 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed |
- risk 0.36cvss 5.5epss 0.00
In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed.…
- risk 0.36cvss 5.5epss 0.00
In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. User interaction is not needed…
- risk 0.36cvss 5.5epss 0.00
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.02
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is…
- risk 0.36cvss 5.5epss 0.00
In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
Page 208 of 323