VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2018-21077LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is a Clipboard content disclosure in the locked state because the keyboard may be used during an emergency call. The Samsung ID is SVE-2017-11107 (April 2018).

  • CVE-2018-21073LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8+, Galaxy S8, Note 8). There is access to Clipboard content in the locked state via the Edge panel. The Samsung ID is SVE-2017-10748 (May 2018).

  • CVE-2018-21046LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is SVE-2018-12911 (November 2018).

  • CVE-2020-11606LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. Information about application preview (in the Secure Folder) leaks on a locked device. The Samsung ID is SVE-2019-16463 (April 2020).

  • CVE-2020-11602LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant leaks clipboard contents on a locked device. The Samsung ID is SVE-2019-16558 (April 2020).

  • CVE-2017-18673LowApr 7, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the Location service on a locked device, making it impossible for the rightful owner to find a stolen device. The Samsung ID is SVE-2017-8524 (May 2017).

  • CVE-2016-11027LowApr 7, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximate attacker can read notifications on the lock screen. The Samsung ID is SVE-2016-7132 (December 2016).

  • CVE-2019-20598LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

  • CVE-2019-20595LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-2019-14545 (July 2019).

  • CVE-2019-20579LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).

  • CVE-2019-20559LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).

  • CVE-2020-10830LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can view notifications by entering many PINs in Lockdown mode. The Samsung ID is SVE-2019-16590 (March 2020).

  • CVE-2019-20534LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (December 2019).

  • CVE-2011-2343LowFeb 12, 2020
    risk 0.16cvss 2.4epss 0.00

    The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.

  • CVE-2024-20051LowApr 1, 2024
    risk 0.15cvss 2.3epss 0.00

    In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.

  • CVE-2024-20045LowApr 1, 2024
    risk 0.15cvss 2.3epss 0.00

    In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08024748; Issue ID:…

  • CVE-2022-20543LowDec 16, 2022
    risk 0.15cvss 2.3epss 0.00

    In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…

  • CVE-2022-20240LowDec 13, 2022
    risk 0.15cvss 2.3epss 0.00

    In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

  • CVE-2022-39906LowDec 8, 2022
    risk 0.15cvss 2.3epss 0.00

    Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.

  • CVE-2022-20261LowAug 12, 2022
    risk 0.15cvss 2.3epss 0.00

    In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-33716LowAug 5, 2022
    risk 0.15cvss 2.3epss 0.00

    An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.

  • CVE-2022-33686LowJul 12, 2022
    risk 0.15cvss 2.3epss 0.00

    Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

  • CVE-2021-25491LowOct 6, 2021
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.

  • CVE-2021-25389LowJun 11, 2021
    risk 0.15cvss 2.3epss 0.00

    Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

  • CVE-2020-8908LowDec 10, 2020
    risk 0.15cvss 3.3epss 0.01

    A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the…

  • CVE-2020-0382LowSep 17, 2020
    risk 0.15cvss 2.3epss 0.00

    In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0029LowMar 10, 2020
    risk 0.15cvss 2.3epss 0.00

    In the WifiConfigManager, there is a possible storage of location history which can only be deleted by triggering a factory reset. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-9455LowSep 6, 2019
    risk 0.15cvss 2.3epss 0.00

    In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0115LowMar 10, 2026
    risk 0.14cvss 2.1epss 0.00

    In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-57840LowDec 24, 2025
    risk 0.14cvss 2.2epss 0.00

    ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

  • CVE-2022-28794LowJun 7, 2022
    risk 0.14cvss 2.2epss 0.00

    Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

  • CVE-2016-3888LowSep 11, 2016
    risk 0.14cvss 2.1epss 0.00

    internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS…

  • CVE-2022-33700LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

  • CVE-2022-33699LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

  • CVE-2022-33693LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

  • CVE-2022-25831LowApr 11, 2022
    risk 0.13cvss 2.0epss 0.00

    Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.

  • CVE-2022-36857LowSep 9, 2022
    risk 0.12cvss 1.9epss 0.00

    Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.

  • CVE-2022-36852LowSep 9, 2022
    risk 0.12cvss 1.9epss 0.00

    Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

  • CVE-2022-30728LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2022-30714LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2015-1538Oct 1, 2015
    risk 0.11cvss epss 0.99

    Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug…

  • CVE-2015-3105Jun 10, 2015
    risk 0.11cvss epss 0.96

    Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143…

  • CVE-2024-4128LowMay 2, 2024
    risk 0.10cvss 2.6epss 0.00

    This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a…

  • CVE-2019-16778LowDec 16, 2019
    risk 0.10cvss 2.6epss 0.01

    In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can produce negative numbers, resulting in accessing out of…

  • CVE-2015-3864Oct 1, 2015
    risk 0.10cvss epss 0.87

    Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability…

  • CVE-2021-29619LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. Passing invalid arguments (e.g., discovered via fuzzing) to `tf.raw_ops.SparseCountSparseOutput` results in segfault. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on…

  • CVE-2021-29618LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. Passing a complex argument to `tf.transpose` at the same time as passing `conjugate=True` argument results in a crash. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on…

  • CVE-2021-29617LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via `CHECK`-fail in `tf.strings.substr` with invalid arguments. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2,…

  • CVE-2021-29616LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. The implementation of TrySimplify(https://github.com/tensorflow/tensorflow/blob/c22d88d6ff33031aa113e48aa3fc9aa74ed79595/tensorflow/core/grappler/optimizers/arithmetic_optimizer.cc#L390-L401) has undefined…

  • CVE-2021-29615LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. The implementation of `ParseAttrValue`(https://github.com/tensorflow/tensorflow/blob/c22d88d6ff33031aa113e48aa3fc9aa74ed79595/tensorflow/core/framework/attr_value_util.cc#L397-L453) can be tricked into stack…

Page 282 of 318