Vendor CVEs
UNISOC
All CVEs
659 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38696 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2025 | In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges. | ||
| CVE-2022-38693 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2025 | In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges. | ||
| CVE-2022-38692 | Cri | 0.64 | 9.8 | 0.00 | Sep 1, 2025 | In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without requiring additional execution privileges. | ||
| CVE-2025-31715 | Cri | 0.64 | 9.8 | 0.02 | Aug 18, 2025 | In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. | ||
| CVE-2022-27250 | Cri | 0.64 | 9.8 | 0.01 | Mar 18, 2022 | The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data. | ||
| CVE-2021-39658 | Cri | 0.64 | 9.8 | 0.01 | Feb 11, 2022 | ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system… | ||
| CVE-2021-39635 | Cri | 0.59 | 9.1 | 0.01 | Feb 11, 2022 | ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid… | ||
| CVE-2025-31713 | Hig | 0.55 | 8.4 | 0.01 | Aug 18, 2025 | In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. | ||
| CVE-2024-39432 | Hig | 0.54 | 8.3 | 0.00 | Sep 27, 2024 | In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed. | ||
| CVE-2024-39431 | Hig | 0.54 | 8.3 | 0.00 | Sep 27, 2024 | In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed. | ||
| CVE-2022-38695 | Hig | 0.51 | 7.8 | 0.00 | Sep 1, 2025 | In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additional execution privileges needed. | ||
| CVE-2022-38694 | Hig | 0.51 | 7.8 | 0.01 | Sep 1, 2025 | In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed. | ||
| CVE-2022-38691 | Hig | 0.51 | 7.8 | 0.00 | Sep 1, 2025 | In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed. | ||
| CVE-2023-52351 | Hig | 0.51 | 7.8 | 0.00 | Apr 8, 2024 | In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | ||
| CVE-2023-42748 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42747 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42746 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42745 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42743 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42740 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42739 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42738 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42736 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42696 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42695 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42694 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42693 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42692 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42691 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42690 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42689 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42688 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42687 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42686 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42685 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-42681 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-40635 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2023 | In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-40634 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2023 | In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed | ||
| CVE-2023-38464 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38460 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38459 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38458 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38456 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38455 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38453 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38452 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38451 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38450 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38449 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38444 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges |
- risk 0.64cvss 9.8epss 0.01
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
- risk 0.64cvss 9.8epss 0.01
In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
- risk 0.64cvss 9.8epss 0.00
In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without requiring additional execution privileges.
- risk 0.64cvss 9.8epss 0.02
In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed.
- risk 0.64cvss 9.8epss 0.01
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.
- risk 0.64cvss 9.8epss 0.01
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system…
- risk 0.59cvss 9.1epss 0.01
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid…
- risk 0.55cvss 8.4epss 0.01
In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
- risk 0.54cvss 8.3epss 0.00
In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.
- risk 0.54cvss 8.3epss 0.00
In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.01
In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Page 1 of 14