CVE-2023-21270
- EPSS 0.09%
- Veröffentlicht 19.11.2024 18:15:19
- Zuletzt bearbeitet 18.12.2024 14:22:02
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege...
CVE-2017-13315
- EPSS 0.1%
- Veröffentlicht 19.11.2024 18:15:18
- Zuletzt bearbeitet 18.12.2024 14:23:37
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional exec...
CVE-2018-9338
- EPSS 0.12%
- Veröffentlicht 19.11.2024 18:15:18
- Zuletzt bearbeitet 22.11.2024 15:48:50
In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVE-2024-50302
- EPSS 0.81%
- Veröffentlicht 19.11.2024 02:16:32
- Zuletzt bearbeitet 12.05.2026 18:47:16
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that i...
CVE-2017-13310
- EPSS 0.07%
- Veröffentlicht 15.11.2024 22:15:14
- Zuletzt bearbeitet 17.12.2024 20:29:35
In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional e...
CVE-2017-13311
- EPSS 0.07%
- Veröffentlicht 15.11.2024 22:15:14
- Zuletzt bearbeitet 18.12.2024 15:00:52
In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additi...
CVE-2017-13312
- EPSS 0.07%
- Veröffentlicht 15.11.2024 22:15:14
- Zuletzt bearbeitet 18.12.2024 14:49:59
In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execu...
CVE-2017-13313
- EPSS 0.22%
- Veröffentlicht 15.11.2024 22:15:14
- Zuletzt bearbeitet 18.12.2024 14:44:13
In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileg...
CVE-2017-13314
- EPSS 0.07%
- Veröffentlicht 15.11.2024 22:15:14
- Zuletzt bearbeitet 18.12.2024 14:36:21
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supp...
CVE-2017-13309
- EPSS 0.08%
- Veröffentlicht 15.11.2024 21:15:05
- Zuletzt bearbeitet 17.12.2024 20:31:02
In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...