CVE-2020-0259
- EPSS 0.01%
- Veröffentlicht 11.08.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:11
In android_verity_ctr of dm-android-verity.c, there is a possible way to modify a dm-verity protected filesystem due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVE-2020-0108
- EPSS 1.84%
- Veröffentlicht 11.08.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:55
In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
- EPSS 0.01%
- Veröffentlicht 11.08.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:53:09
In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privilege...
CVE-2020-0107
- EPSS 0.01%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:52:55
In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...
CVE-2020-0122
- EPSS 0.01%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:52:56
In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. Us...
- EPSS 0.64%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:08
In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code execution when processing a proxy configuration with no additional execution privileges needed. User interact...
- EPSS 5.6%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:08
In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction...
CVE-2020-0226
- EPSS 0.01%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:08
In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not n...
CVE-2020-0227
- EPSS 0.01%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:08
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no ad...
CVE-2020-0228
- EPSS 0.12%
- Veröffentlicht 17.07.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:08
There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-156333723