VYPR

Vendor CVEs

Google

All CVEs

16,115 total · sorted by risk
  • CVE-2024-39430MedJul 1, 2024
    risk 0.33cvss 5.1epss 0.00

    In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2024-39429MedJul 1, 2024
    risk 0.33cvss 5.1epss 0.00

    In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2024-39427MedJul 1, 2024
    risk 0.33cvss 5.1epss 0.00

    In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2024-27230MedMar 11, 2024
    risk 0.33cvss 5.1epss 0.00

    In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2024-27223MedMar 11, 2024
    risk 0.33cvss 5.1epss 0.00

    In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure after authenticating the cell connection with no additional execution privileges needed.…

  • CVE-2024-0019MedFeb 16, 2024
    risk 0.33cvss 5.0epss 0.00

    In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User…

  • CVE-2023-21307MedOct 30, 2023
    risk 0.33cvss 5.0epss 0.00

    In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2023-44128MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the…

  • CVE-2023-44121MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action…

  • CVE-2023-21190MedJun 28, 2023
    risk 0.33cvss 5.0epss 0.00

    In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed.…

  • CVE-2023-21090MedApr 19, 2023
    risk 0.33cvss 5.0epss 0.00

    In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-0460MedMar 1, 2023
    risk 0.33cvss 5.1epss 0.00

    The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from YouTube Main App by…

  • CVE-2022-20521MedDec 16, 2022
    risk 0.33cvss 5.0epss 0.00

    In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20394MedOct 11, 2022
    risk 0.33cvss 5.0epss 0.00

    In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2022-39855MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

  • CVE-2022-36848MedSep 9, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

  • CVE-2022-20266MedAug 12, 2022
    risk 0.33cvss 5.0epss 0.00

    In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2022-33731MedAug 5, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

  • CVE-2022-33695MedJul 12, 2022
    risk 0.33cvss 5.1epss 0.00

    Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

  • CVE-2022-20196MedJun 15, 2022
    risk 0.33cvss 5.0epss 0.00

    In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID:…

  • CVE-2022-20195MedJun 15, 2022
    risk 0.33cvss 5.0epss 0.00

    In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-28780MedMay 3, 2022
    risk 0.33cvss 5.0epss 0.00

    Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

  • CVE-2021-1023MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2021-0973MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0952MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-0919MedDec 15, 2021
    risk 0.33cvss 5.0epss 0.00

    In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-25503MedNov 5, 2021
    risk 0.33cvss 5.0epss 0.00

    Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

  • CVE-2021-0687MedOct 6, 2021
    risk 0.33cvss 5.0epss 0.00

    In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11…

  • CVE-2021-25453MedSep 9, 2021
    risk 0.33cvss 5.1epss 0.00

    Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

  • CVE-2021-0569MedJun 22, 2021
    risk 0.33cvss 5.0epss 0.00

    In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-25340MedMar 4, 2021
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.

  • CVE-2021-0322MedJan 11, 2021
    risk 0.33cvss 5.0epss 0.00

    In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android;…

  • CVE-2020-0338MedSep 17, 2020
    risk 0.33cvss 5.0epss 0.00

    In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID:…

  • CVE-2020-0093MedMay 14, 2020
    risk 0.33cvss 5.0epss 0.00

    In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0092MedMay 14, 2020
    risk 0.33cvss 5.0epss 0.00

    In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification content due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-0031MedMar 10, 2020
    risk 0.33cvss 5.0epss 0.00

    In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to display sensitive information to the user inappropriately. This could lead to local information disclosure with no additional execution privileges needed. User…

  • CVE-2014-7951MedFeb 20, 2020
    risk 0.33cvss 4.6epss 0.01

    Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar archive headers.

  • CVE-2019-9421MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In libandroidfw, there is a possible OOB read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215250

  • CVE-2019-9383MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9356MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9344MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9296MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112162089

  • CVE-2019-9251MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120274615

  • CVE-2019-9246MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120428637

  • CVE-2019-9244MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120865977

  • CVE-2019-9242MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121035878

  • CVE-2019-9240MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121150966

  • CVE-2019-9239MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121263487

  • CVE-2019-9236MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122322613

  • CVE-2019-9235MedSep 27, 2019
    risk 0.33cvss 5.0epss 0.00

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122323053

Page 242 of 323