VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2022-20173CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

  • CVE-2022-20171CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A

  • CVE-2022-20170CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A

  • CVE-2022-20167CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

  • CVE-2022-20164CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A

  • CVE-2022-20160CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A

  • CVE-2022-20145CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.07

    In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is…

  • CVE-2022-20140CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.09

    In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20130CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.09

    In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20127CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.07

    In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2022-20120CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A

  • CVE-2021-39737CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A

  • CVE-2021-39723CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A

  • CVE-2021-39720CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A

  • CVE-2021-39710CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A

  • CVE-2021-39708CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-0306HigFeb 12, 2022
    risk 0.64cvss 8.8epss 0.85

    Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-39675CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.06

    In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39658CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system…

  • CVE-2021-39616CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

  • CVE-2021-22566CriJan 18, 2022
    risk 0.64cvss 9.8epss 0.00

    An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kernel-mode pages from user-mode. An…

  • CVE-2021-39623CriJan 14, 2022
    risk 0.64cvss 9.8epss 0.02

    In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1049CriJan 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722

  • CVE-2021-39655CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A

  • CVE-2021-39645CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A

  • CVE-2021-39644CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A

  • CVE-2021-39641CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A

  • CVE-2021-0956CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for…

  • CVE-2021-0889CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.02

    In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2021-0869CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.01

    In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2021-0515CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.01

    In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0516CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.02

    In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0324CriJun 14, 2021
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android SoCAndroid ID: A-175402462

  • CVE-2021-0474CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.03

    In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11…

  • CVE-2021-0430CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.03

    In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0397CriMar 10, 2021
    risk 0.64cvss 9.8epss 0.06

    In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11…

  • CVE-2021-0396CriMar 10, 2021
    risk 0.64cvss 9.8epss 0.02

    In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed.…

  • CVE-2021-21132CriFeb 9, 2021
    risk 0.64cvss 9.6epss 0.23

    Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2021-26689CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).

  • CVE-2021-26688CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).

  • CVE-2021-26687CriFeb 4, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).

  • CVE-2021-0316CriJan 11, 2021
    risk 0.64cvss 9.8epss 0.03

    In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2020-0471CriJan 11, 2021
    risk 0.64cvss 9.8epss 0.02

    In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no…

  • CVE-2019-25004CriDec 31, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the flatbuffers crate before 0.6.1 for Rust. Arbitrary bytes can be reinterpreted as a bool, defeating soundness.

  • CVE-2020-35551CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung…

  • CVE-2020-35550CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).

  • CVE-2020-27068CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel

  • CVE-2020-0456CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.01

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843

  • CVE-2020-0457CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.01

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170367562

  • CVE-2020-0455CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.01

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170372514

Page 6 of 318