Google

Android

8032 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:14

In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

  • EPSS 0.41%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:14

In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is...

  • EPSS 0.37%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:14

In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Prod...

  • EPSS 44.3%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:14

In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation...

  • EPSS 0.34%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:14

In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for ...

  • EPSS 0.76%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:15

In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitati...

  • EPSS 0.02%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:15

In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. ...

  • EPSS 0.02%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:15

In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset protection bypass with no additional privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: An...

  • EPSS 0.31%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:15

In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...

  • EPSS 0.02%
  • Veröffentlicht 08.07.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:15

In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier systems with no additional execution privileges needed. ...