Vendor CVEs
All CVEs
15,856 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21250 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-20918 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21066 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2023 | In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | ||
| CVE-2022-48335 | Cri | 0.64 | 9.8 | 0.01 | Jun 26, 2023 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow. | ||
| CVE-2023-21130 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-0945 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2023 | In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-0701 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2023 | In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2021-0877 | Cri | 0.64 | 9.8 | 0.00 | May 15, 2023 | Product: AndroidVersions: Android SoCAndroid ID: A-273754094 | ||
| CVE-2023-21096 | Cri | 0.64 | 9.8 | 0.00 | Apr 19, 2023 | In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L… | ||
| CVE-2023-21058 | Cri | 0.64 | 9.8 | 0.00 | Mar 24, 2023 | In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21057 | Cri | 0.64 | 9.8 | 0.00 | Mar 24, 2023 | In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-20954 | Cri | 0.64 | 9.8 | 0.00 | Mar 24, 2023 | In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20951 | Cri | 0.64 | 9.8 | 0.00 | Mar 24, 2023 | In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-42499 | Cri | 0.64 | 9.8 | 0.01 | Mar 24, 2023 | In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-42498 | Cri | 0.64 | 9.8 | 0.01 | Mar 24, 2023 | In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | ||
| CVE-2022-20532 | Cri | 0.64 | 9.8 | 0.00 | Mar 24, 2023 | In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-1529 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High) | ||
| CVE-2023-20946 | Cri | 0.64 | 9.8 | 0.00 | Feb 28, 2023 | In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-42529 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A | ||
| CVE-2022-20473 | Cri | 0.64 | 9.8 | 0.09 | Dec 13, 2022 | In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20472 | Cri | 0.64 | 9.8 | 0.07 | Dec 13, 2022 | In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20391 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000 | ||
| CVE-2022-20390 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002 | ||
| CVE-2022-20389 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004 | ||
| CVE-2022-20388 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323 | ||
| CVE-2022-20387 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324 | ||
| CVE-2022-20386 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328 | ||
| CVE-2022-20385 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android… | ||
| CVE-2021-0942 | Cri | 0.64 | 9.8 | 0.00 | Sep 13, 2022 | The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read.… | ||
| CVE-2022-26447 | Cri | 0.64 | 9.8 | 0.01 | Sep 6, 2022 | In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478. | ||
| CVE-2022-20122 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2022 | The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid… | ||
| CVE-2021-39815 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2022 | The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid… | ||
| CVE-2022-2587 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2022 | Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata. | ||
| CVE-2022-20405 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A | ||
| CVE-2022-20403 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A | ||
| CVE-2022-20402 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A | ||
| CVE-2022-20400 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2022 | In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | ||
| CVE-2022-20384 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A | ||
| CVE-2022-20381 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A | ||
| CVE-2022-20378 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A | ||
| CVE-2022-20365 | Cri | 0.64 | 9.8 | 0.00 | Aug 11, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A | ||
| CVE-2022-20237 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2022 | In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20361 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2022 | In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20239 | Cri | 0.64 | 9.8 | 0.00 | Aug 10, 2022 | remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions:… | ||
| CVE-2022-20238 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2022 | 'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions:… | ||
| CVE-2022-20229 | Cri | 0.64 | 9.8 | 0.03 | Jul 13, 2022 | In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20222 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2022 | In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12… | ||
| CVE-2022-20216 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2022 | android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916 | ||
| CVE-2022-20210 | Cri | 0.64 | 9.8 | 0.04 | Jun 15, 2022 | The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which… | ||
| CVE-2022-20191 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A |
- risk 0.64cvss 9.8epss 0.01
In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
- risk 0.64cvss 9.8epss 0.01
Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow.
- risk 0.64cvss 9.8epss 0.01
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.00
In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android SoCAndroid ID: A-273754094
- risk 0.64cvss 9.8epss 0.00
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L…
- risk 0.64cvss 9.8epss 0.00
In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.00
In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.00
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.00
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.01
In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.01
In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
- risk 0.64cvss 9.8epss 0.00
In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.01
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
- risk 0.64cvss 9.8epss 0.00
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
- risk 0.64cvss 9.8epss 0.09
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.07
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
- risk 0.64cvss 9.8epss 0.00
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
- risk 0.64cvss 9.8epss 0.00
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android…
- risk 0.64cvss 9.8epss 0.00
The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read.…
- risk 0.64cvss 9.8epss 0.01
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.
- risk 0.64cvss 9.8epss 0.00
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid…
- risk 0.64cvss 9.8epss 0.00
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid…
- risk 0.64cvss 9.8epss 0.01
Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
- risk 0.64cvss 9.8epss 0.01
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
- risk 0.64cvss 9.8epss 0.01
In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.01
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.00
remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.01
'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.03
In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.01
In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12…
- risk 0.64cvss 9.8epss 0.01
android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916
- risk 0.64cvss 9.8epss 0.04
The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which…
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A
Page 5 of 318