CVE-2020-0021
- EPSS 1.9%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. This could lead to remote denial of service with User execution privileges needed. User interaction is...
CVE-2020-0022
- EPSS 6.21%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction...
CVE-2020-0023
- EPSS 0.11%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:45
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluet...
CVE-2020-0026
- EPSS 0.04%
- Veröffentlicht 13.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:46
In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVE-2011-2343
- EPSS 0.02%
- Veröffentlicht 12.02.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 01:28:04
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
CVE-2011-3901
- EPSS 0.29%
- Veröffentlicht 12.02.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 01:31:30
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
- EPSS 2.2%
- Veröffentlicht 07.02.2020 16:15:09
- Zuletzt bearbeitet 21.11.2024 02:16:33
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.
CVE-2019-11516
- EPSS 0.62%
- Veröffentlicht 05.02.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:15
An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Extended Inquiry Responses (EIRs) are improperly handled, which causes a heap-based buffer overflow during device inquiry. This over...
CVE-2019-19273
- EPSS 0.01%
- Veröffentlicht 04.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:28
On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.
CVE-2015-1525
- EPSS 0.05%
- Veröffentlicht 24.01.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 02:25:35
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.