CVE-2017-13314
- EPSS 0.01%
- Veröffentlicht 15.11.2024 22:15:14
- Zuletzt bearbeitet 18.12.2024 14:36:21
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supp...
CVE-2017-13309
- EPSS 0.04%
- Veröffentlicht 15.11.2024 21:15:05
- Zuletzt bearbeitet 17.12.2024 20:31:02
In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVE-2017-13227
- EPSS 0.06%
- Veröffentlicht 14.11.2024 23:15:05
- Zuletzt bearbeitet 20.11.2024 17:35:01
In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-43083
- EPSS 0.09%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 17.12.2024 20:03:05
In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exp...
CVE-2024-43084
- EPSS 0.07%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 13.03.2025 19:15:47
In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-43085
- EPSS 0.06%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 18.12.2024 16:57:04
In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution priv...
CVE-2024-43086
- EPSS 0.06%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 18.12.2024 16:58:17
In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges need...
CVE-2024-43087
- EPSS 0.07%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 18.12.2024 16:59:38
In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of pri...
CVE-2024-43088
- EPSS 0.39%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 17.12.2024 21:16:19
In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead to local escalation of privilege across user boundarie...
CVE-2024-43089
- EPSS 0.06%
- Veröffentlicht 13.11.2024 18:15:21
- Zuletzt bearbeitet 17.12.2024 21:04:38
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...