Google

Android

8032 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 19.06.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:40:04

In rw_t3t_act_handle_ndef_detect_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exp...

  • EPSS 0.1%
  • Veröffentlicht 19.06.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:40:05

In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interac...

  • EPSS 0.12%
  • Veröffentlicht 19.06.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:40:05

In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in a privileg...

  • EPSS 0.08%
  • Veröffentlicht 19.06.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:40:05

In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

  • EPSS 0.19%
  • Veröffentlicht 19.06.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:40:05

In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitat...

  • EPSS 0.5%
  • Veröffentlicht 19.06.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:37:50

In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for e...

  • EPSS 0.5%
  • Veröffentlicht 19.06.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:37:50

In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for expl...

  • EPSS 0.02%
  • Veröffentlicht 19.06.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:02

In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

  • EPSS 0.09%
  • Veröffentlicht 19.06.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:03

In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. This could lead to local escalation of privilege on a locked device with no additional execution privil...

  • EPSS 0.13%
  • Veröffentlicht 19.06.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:03

In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not nee...