CVE-2020-0027
- EPSS 0.03%
- Veröffentlicht 13.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:52:46
In HidRawSensor::batch of HidRawSensor.cpp, there is a possible out of bounds write due to an unexpected switch fallthrough. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVE-2020-0028
- EPSS 0.87%
- Veröffentlicht 13.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:52:46
In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for e...
- EPSS 0.03%
- Veröffentlicht 13.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:52:46
In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVE-2019-2200
- EPSS 0.01%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege with User execution privileges n...
CVE-2020-0005
- EPSS 0.04%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:43
In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...
CVE-2020-0014
- EPSS 1.17%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:44
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploita...
CVE-2020-0015
- EPSS 0.01%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...
CVE-2020-0017
- EPSS 0.03%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for e...
CVE-2020-0018
- EPSS 0.04%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution privileges needed. User interaction is not needed for exploitation.Produ...
CVE-2020-0020
- EPSS 0.03%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User inte...