VYPR

Vendor CVEs

Google

All CVEs

16,116 total · sorted by risk
  • CVE-2023-30913MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-21211MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…

  • CVE-2023-21205MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21200MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21198MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21177MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2023-21173MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21168MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21167MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21160MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In BuildSetTcsFci of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21155MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In BuildSetRadioNode of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21152MedJun 28, 2023
    risk 0.36cvss 5.5epss 0.00

    In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2023-21143MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21142MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21141MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21137MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12…

  • CVE-2023-21136MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21105MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-30915MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30914MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30866MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2023-30865MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2022-48448MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48447MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48446MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48445MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48444MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48443MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48442MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48441MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48440MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48391MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2023-21118MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21112MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-21111MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21104MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:…

  • CVE-2023-21103MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20930MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-20914MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User…

  • CVE-2023-20706MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.

  • CVE-2023-20705MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.

  • CVE-2023-20704MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

  • CVE-2023-20703MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767853; Issue ID: ALPS07767853.

  • CVE-2022-48379MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48378MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48377MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48376MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48375MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.

  • CVE-2022-48370MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.

Page 214 of 323