|
21
|
6.6
-
|
MEDIUM
Physics
|
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2025-20639
|
cpe:2.3:o:google:android:15.0:* cpe:2.3:o:google:android:14.0:* cpe:2.3:o:google:android:13.0:* cpe:2.3:o:goog…
|
|
|
|
|
2025-02-5 00:24
2025-02-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
5.5
-
|
MEDIUM
Local
|
In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges neede…
|
CWE-862
Missing Authorization
|
CVE-2018-9406
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2025-01-24 04:55
2025-01-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
7.8
-
|
HIGH
Local
|
In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution priv…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-9389
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2025-01-24 04:56
2025-01-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
5.5
-
|
MEDIUM
Local
|
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service w…
|
NVD-CWE-noinfo
|
CVE-2017-13322
|
cpe:2.3:o:google:android:8.1:* cpe:2.3:o:google:android:8.0:* cpe:2.3:o:google:android:7.1.2:* cpe:2.3:o:googl…
|
|
|
|
|
2025-01-24 04:54
2025-01-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
7.8
-
|
HIGH
Local
|
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional e…
|
NVD-CWE-noinfo
|
CVE-2023-35685
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2025-01-11 00:30
2025-01-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
9.8
-
|
CRITICAL
Network
|
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges need…
|
NVD-CWE-noinfo
|
CVE-2018-9467
|
cpe:2.3:o:google:android:9.0:* cpe:2.3:o:google:android:8.1:* cpe:2.3:o:google:android:8.0:* cpe:2.3:o:google:…
|
|
|
|
|
2024-11-23 06:27
2024-11-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
8.8
-
|
HIGH
Network
|
In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution pr…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-9466
|
cpe:2.3:o:google:android:8.1:* cpe:2.3:o:google:android:8.0:* cpe:2.3:o:google:android:7.1.2:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-23 06:29
2024-11-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
7.5
-
|
HIGH
Network
|
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges …
|
CWE-125
Out-of-bounds Read
|
CVE-2018-9456
|
cpe:2.3:o:google:android:8.1:* cpe:2.3:o:google:android:8.0:* cpe:2.3:o:google:android:7.1.2:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-23 06:29
2024-11-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
6.5
-
|
MEDIUM
Network
|
In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interacti…
|
NVD-CWE-noinfo
|
CVE-2018-9440
|
cpe:2.3:o:google:android:9.0:* cpe:2.3:o:google:android:8.1:* cpe:2.3:o:google:android:8.0:* cpe:2.3:o:google:…
|
|
|
|
|
2024-11-23 06:30
2024-11-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
8.8
-
|
HIGH
Network
|
In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional execution privileges neede…
|
NVD-CWE-noinfo
|
CVE-2018-9433
|
cpe:2.3:o:google:android:7.1.2:* cpe:2.3:o:google:android:7.1.1:* cpe:2.3:o:google:android:7.0:* cpe:2.3:o:goo…
|
|
|
|
|
2024-11-23 06:13
2024-11-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|