VYPR

Vendor CVEs

Google

All CVEs

16,117 total · sorted by risk
  • CVE-2022-20279MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20278MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20277MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20276MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20275MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20272MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20270MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20263MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20260MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…

  • CVE-2022-20259MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…

  • CVE-2022-20242MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2021-0975MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure of installed packages with no additional execution privileges needed. User…

  • CVE-2021-0735MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2021-0734MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissions, with no additional…

  • CVE-2022-20357MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20355MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2022-20353MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20352MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-20350MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User…

  • CVE-2022-20230MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20227MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:…

  • CVE-2022-20225MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20219MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-21764MedJul 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID:…

  • CVE-2022-21763MedJul 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID:…

  • CVE-2022-20206MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-20205MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20200MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20172MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20146MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This could lead to local information disclosure of private files with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20143MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20129MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.00

    In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not…

  • CVE-2022-21749MedJun 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511058; Issue ID:…

  • CVE-2022-21748MedJun 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06511030; Issue ID: ALPS06511030.

  • CVE-2022-20121MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20119MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20117MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20115MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User…

  • CVE-2022-20112MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2022-20011MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39700MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39670MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20104MedMay 3, 2022
    risk 0.36cvss 5.5epss 0.00

    In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID:…

  • CVE-2022-20101MedMay 3, 2022
    risk 0.36cvss 5.5epss 0.00

    In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06270870.

  • CVE-2022-20092MedMay 3, 2022
    risk 0.36cvss 5.5epss 0.00

    In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366061; Issue ID: ALPS06366061.

  • CVE-2021-39800MedApr 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39791MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction…

  • CVE-2021-39788MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2021-39779MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39778MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

Page 220 of 323