VYPR

Vendor CVEs

Google

All CVEs

16,106 total · sorted by risk
  • CVE-2024-40677HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2024-40672HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-40670HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-40669HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-40651HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-40649HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-34748HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-34733HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-34732HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20104HigNov 4, 2024
    risk 0.55cvss 8.4epss 0.00

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.

  • CVE-2024-29749HigApr 5, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-29746HigApr 5, 2024
    risk 0.55cvss 8.4epss 0.00

    In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20053HigApr 1, 2024
    risk 0.55cvss 8.4epss 0.00

    In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.

  • CVE-2024-27236HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27226HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27220HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27219HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27213HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27209HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27208HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27205HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27204HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_set_gov_active of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-25993HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_reset_tmu_trip_counter of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-25988HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-25985HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-22005HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    there is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-20029HigMar 4, 2024
    risk 0.55cvss 8.4epss 0.00

    In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477406; Issue ID: MSV-1010.

  • CVE-2023-4164HigJan 2, 2024
    risk 0.55cvss 8.4epss 0.00

    There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.

  • CVE-2023-4427HigAug 23, 2023
    risk 0.55cvss 8.1epss 0.35

    Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-3708CriOct 28, 2022
    risk 0.55cvss 9.6epss 0.01

    The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for…

  • CVE-2022-2856MedKEVSep 26, 2022
    risk 0.55cvss 6.5epss 0.05

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

  • CVE-2022-33704HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-33703HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30756HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.

  • CVE-2022-30754HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.

  • CVE-2022-30713HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30712HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30711HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30710HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-20111HigMay 3, 2022
    risk 0.55cvss 8.4epss 0.00

    In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ID: ALPS06366069.

  • CVE-2022-27836HigApr 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary…

  • CVE-2022-27830HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27829HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27828HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27827HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27826HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-23428HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

  • CVE-2018-21070HigApr 8, 2020
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity check. The Samsung ID is SVE-2018-11552 (May 2018).

  • CVE-2018-21082HigApr 8, 2020
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use screen lock type to unpin" option. The Samsung ID is SVE-2017-11106 (February 2018).

  • CVE-2018-9363HigNov 6, 2018
    risk 0.55cvss 8.4epss 0.00

    In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588…

Page 69 of 323