Google

Android

7895 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 13.11.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:40:26

In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

  • EPSS 0.05%
  • Veröffentlicht 13.11.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:40:29

In getUserCount and getCount of UserSwitcherController.java, there is possible new user creation due to a logic error. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution...

  • EPSS 0.61%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:06

In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...

  • EPSS 0.01%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:24

In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.P...

  • EPSS 0.01%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:24

In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Admin app installed with no indication to the user, wi...

  • EPSS 0.03%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:24

In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...

  • EPSS 0.69%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:24

In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 A...

  • EPSS 0.02%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:24

In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privileges needed...

  • EPSS 0.69%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:25

In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8...

  • EPSS 0.01%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:25

In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andro...