Google

Android

7931 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 15.12.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:43:18

In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Pro...

  • EPSS 0.05%
  • Veröffentlicht 15.12.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:43:19

In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Prod...

  • EPSS 0.01%
  • Veröffentlicht 15.12.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:43:19

In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...

  • EPSS 0.37%
  • Veröffentlicht 15.12.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:43:19

In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploi...

  • EPSS 0.04%
  • Veröffentlicht 15.12.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:43:19

In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...

  • EPSS 0.02%
  • Veröffentlicht 15.12.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:43:19

In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder t...

  • EPSS 0.03%
  • Veröffentlicht 15.12.2021 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:42:43

In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local ...

  • EPSS 0.01%
  • Veröffentlicht 15.12.2021 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:43:04

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed fo...

  • EPSS 0.47%
  • Veröffentlicht 15.12.2021 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:43:04

In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploi...

  • EPSS 0.03%
  • Veröffentlicht 15.12.2021 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:43:05

In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. ...