Google

Android

7895 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.9%
  • Veröffentlicht 13.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:45

In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. This could lead to remote denial of service with User execution privileges needed. User interaction is...

Exploit
  • EPSS 6.21%
  • Veröffentlicht 13.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:45

In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction...

  • EPSS 0.11%
  • Veröffentlicht 13.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:45

In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluet...

  • EPSS 0.04%
  • Veröffentlicht 13.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:46

In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

  • EPSS 0.02%
  • Veröffentlicht 12.02.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 01:28:04

The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 12.02.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 01:31:30

Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.

Exploit
  • EPSS 2.2%
  • Veröffentlicht 07.02.2020 16:15:09
  • Zuletzt bearbeitet 21.11.2024 02:16:33

A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.

  • EPSS 0.62%
  • Veröffentlicht 05.02.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:21:15

An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Extended Inquiry Responses (EIRs) are improperly handled, which causes a heap-based buffer overflow during device inquiry. This over...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 04.02.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 04:34:28

On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.

  • EPSS 0.05%
  • Veröffentlicht 24.01.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 02:25:35

audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.