CVE-2020-0368
- EPSS 0.02%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:23
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not nee...
CVE-2020-0473
- EPSS 0.01%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:34
In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it ov...
- EPSS 0.01%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:34
In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...
CVE-2020-0475
- EPSS 0.05%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:34
In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
CVE-2020-0476
- EPSS 0.02%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:34
In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product:...
CVE-2020-0477
- EPSS 0.02%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:35
In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no additional exe...
CVE-2020-0478
- EPSS 0.06%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:35
In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitatio...
CVE-2020-0479
- EPSS 0.04%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:35
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with no additiona...
CVE-2020-0480
- EPSS 0.05%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:35
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider wi...
CVE-2020-0481
- EPSS 0.01%
- Veröffentlicht 15.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:35
In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, with no additional execution privileges needed. User...