CVE-2026-56952
- EPSS 0.08%
- Veröffentlicht 06.10.2026 18:20:57
- Zuletzt bearbeitet 07.10.2026 04:18:10
In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed ...
CVE-2026-56936
- EPSS 0.1%
- Veröffentlicht 06.10.2026 18:20:56
- Zuletzt bearbeitet 06.10.2026 20:03:40
In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
- EPSS 0.05%
- Veröffentlicht 06.10.2026 18:20:55
- Zuletzt bearbeitet 07.10.2026 04:18:09
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-55330
- EPSS 0.3%
- Veröffentlicht 06.10.2026 18:20:54
- Zuletzt bearbeitet 07.10.2026 04:18:09
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for e...
CVE-2026-55307
- EPSS 0.07%
- Veröffentlicht 06.10.2026 18:20:53
- Zuletzt bearbeitet 06.10.2026 20:03:40
In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploi...
CVE-2026-0198
- EPSS 0.09%
- Veröffentlicht 06.10.2026 18:20:52
- Zuletzt bearbeitet 06.10.2026 20:03:40
In is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28648
- EPSS 0.07%
- Veröffentlicht 05.10.2026 18:39:22
- Zuletzt bearbeitet 07.10.2026 13:06:17
In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28647
- EPSS 0.08%
- Veröffentlicht 05.10.2026 18:39:21
- Zuletzt bearbeitet 07.10.2026 13:07:56
In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVE-2026-28641
- EPSS 0.08%
- Veröffentlicht 05.10.2026 18:39:20
- Zuletzt bearbeitet 07.10.2026 13:08:22
In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee...
CVE-2026-28640
- EPSS 0.08%
- Veröffentlicht 05.10.2026 18:39:19
- Zuletzt bearbeitet 07.10.2026 13:08:48
In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. U...