VYPR

Vendor CVEs

Google

All CVEs

16,106 total · sorted by risk
  • CVE-2022-29191MedMay 20, 2022
    risk 0.29cvss 5.5epss 0.00

    TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.GetSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial…

  • CVE-2022-20107MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID: DTV03330673.

  • CVE-2022-20103MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06282684.

  • CVE-2022-20102MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296405.

  • CVE-2022-20100MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06270804.

  • CVE-2022-20098MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06419017.

  • CVE-2022-20096MedMay 3, 2022
    risk 0.29cvss 4.4epss 0.00

    In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06419003; Issue ID: ALPS06419003.

  • CVE-2022-27833MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

  • CVE-2022-27574MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.

  • CVE-2022-27573MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attackers.

  • CVE-2022-20079MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05857289.

  • CVE-2022-20076MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    In ged, there is a possible memory corruption due to an incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID: ALPS05839556.

  • CVE-2022-20066MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.00

    In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171729; Issue ID:…

  • CVE-2021-39730MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In TBD of TBD, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:…

  • CVE-2021-39724MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In TuningProviderBase::GetTuningTreeSet of tuning_provider_base.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-39722MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In ProtocolStkProactiveCommandAdapter::Init of protocolstkadapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-39717MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In iaxxx_btp_write_words of iaxxx-btp.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39715MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39711MedMar 16, 2022
    risk 0.29cvss 4.4epss 0.00

    In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-24930MedMar 10, 2022
    risk 0.29cvss 4.4epss 0.00

    An Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Release allows untrusted applications to reset default app settings without a proper permission

  • CVE-2022-25327MedFeb 25, 2022
    risk 0.29cvss 5.5epss 0.00

    The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users…

  • CVE-2022-25326MedFeb 25, 2022
    risk 0.29cvss 5.5epss 0.00

    fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories…

  • CVE-2022-24925MedFeb 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.

  • CVE-2022-23426MedFeb 11, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

  • CVE-2022-20035MedFeb 9, 2022
    risk 0.29cvss 4.4epss 0.00

    In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ID: ALPS06171675.

  • CVE-2022-20033MedFeb 9, 2022
    risk 0.29cvss 4.4epss 0.00

    In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973; Issue ID: ALPS05862973.

  • CVE-2022-20029MedFeb 9, 2022
    risk 0.29cvss 4.4epss 0.00

    In cmdq driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05747150; Issue ID: ALPS05747150.

  • CVE-2021-39680MedJan 14, 2022
    risk 0.29cvss 4.4epss 0.00

    In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-22270MedJan 10, 2022
    risk 0.29cvss 4.4epss 0.00

    An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.

  • CVE-2022-20018MedJan 4, 2022
    risk 0.29cvss 4.4epss 0.00

    In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05863018; Issue ID: ALPS05863018.

  • CVE-2022-20015MedJan 4, 2022
    risk 0.29cvss 4.4epss 0.00

    In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862966; Issue ID: ALPS05862966.

  • CVE-2021-0902MedDec 17, 2021
    risk 0.29cvss 4.4epss 0.00

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05656484.

  • CVE-2021-0900MedDec 17, 2021
    risk 0.29cvss 4.4epss 0.00

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672055.

  • CVE-2021-0677MedDec 17, 2021
    risk 0.29cvss 4.4epss 0.00

    In ccu driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827154; Issue ID: ALPS05827154.

  • CVE-2021-0676MedDec 17, 2021
    risk 0.29cvss 4.4epss 0.00

    In geniezone driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05863009; Issue ID: ALPS05863009.

  • CVE-2021-39657MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39647MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In mon_smc_load_sp of gs101-sc/plat/samsung/exynos/soc/exynos9845/smc_booting.S, there is a possible reinitialization of TEE due to improper locking. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-39637MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In CreateDeviceInfo of trusty_remote_provisioning_context.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39636MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1047MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In valid_ipc_dram_addr of cm_access_control.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-1046MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In lwis_dpm_update_clock of lwis_device_dpm.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1042MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In dsi_panel_debugfs_read_cmdset of dsi_panel.c, there is a possible disclosure of freed kernel heap memory due to a use after free. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1008MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for…

  • CVE-2021-1007MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In btu_hcif_process_event of btu_hcif.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-1006MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0996MedDec 15, 2021
    risk 0.29cvss 4.5epss 0.00

    In nfaHciCallback of HciEventManager.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0961MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-0958MedDec 15, 2021
    risk 0.29cvss 4.4epss 0.00

    In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0666MedNov 18, 2021
    risk 0.29cvss 4.4epss 0.00

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672086; Issue ID: ALPS05672086.

  • CVE-2021-0665MedNov 18, 2021
    risk 0.29cvss 4.4epss 0.00

    In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672113; Issue ID: ALPS05672113.

Page 253 of 323