CVE-2020-0139
- EPSS 0.02%
- Veröffentlicht 11.06.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:52:58
In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmware. System execution privileges are needed and use...
CVE-2020-0113
- EPSS 0.11%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:55
In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVE-2020-0114
- EPSS 0.03%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:55
In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution pr...
CVE-2020-0115
- EPSS 0.01%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:55
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges nee...
CVE-2020-0116
- EPSS 0.01%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:56
In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interact...
- EPSS 0.87%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:56
In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2020-0118
- EPSS 0.01%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:56
In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for expl...
CVE-2020-0119
- EPSS 0.14%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:56
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileg...
CVE-2020-0121
- EPSS 0.03%
- Veröffentlicht 10.06.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:56
In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploi...
CVE-2020-13842
- EPSS 0.02%
- Veröffentlicht 05.06.2020 00:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:59
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).