CVE-2020-0434
- EPSS 0.02%
- Veröffentlicht 17.09.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:30
In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVE-2020-0387
- EPSS 0.03%
- Veröffentlicht 17.09.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:25
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interact...
CVE-2020-0403
- EPSS 0.01%
- Veröffentlicht 17.09.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:27
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed f...
CVE-2020-0427
- EPSS 0.16%
- Veröffentlicht 17.09.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:30
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVE-2020-0428
- EPSS 0.02%
- Veröffentlicht 17.09.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:30
In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android ke...
CVE-2020-0404
- EPSS 0.18%
- Veröffentlicht 17.09.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 04:53:27
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not...
CVE-2020-0407
- EPSS 0.01%
- Veröffentlicht 17.09.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 04:53:27
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits. This may ...
CVE-2020-0383
- EPSS 0.14%
- Veröffentlicht 17.09.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:25
In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is nee...
CVE-2020-0384
- EPSS 0.14%
- Veröffentlicht 17.09.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:25
In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed f...
CVE-2020-0385
- EPSS 0.14%
- Veröffentlicht 17.09.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:53:25
In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed ...