Google

Android

7931 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 10.11.2020 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:53:31

In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional ex...

  • EPSS 0.01%
  • Veröffentlicht 10.11.2020 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:53:31

In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant...

  • EPSS 0.15%
  • Veröffentlicht 08.11.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:37

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).

  • EPSS 0.02%
  • Veröffentlicht 08.11.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:37

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID...

  • EPSS 0.07%
  • Veröffentlicht 08.11.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:37

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure application allows attackers to bypass authentication for a locked Gallery application via the Reminder application. The Samsung ID is SV...

  • EPSS 0.08%
  • Veröffentlicht 08.11.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:38

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung...

  • EPSS 0.15%
  • Veröffentlicht 08.11.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:38

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200024 (November 2020).

  • EPSS 0.13%
  • Veröffentlicht 08.11.2020 05:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:38

An issue was discovered on LG mobile devices with Android OS 10 software. The Wi-Fi subsystem may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200025 (November 2020).

  • EPSS 0.24%
  • Veröffentlicht 14.10.2020 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:53:28

In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for expl...

  • EPSS 0.02%
  • Veröffentlicht 14.10.2020 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:53:29

In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check. This could lead to local information disclosure with no additional execution privileges nee...