|
231
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0097
|
2026-06-3 22:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
7.8 |
HIGH
Local
|
google
|
android
|
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional ex…
New
|
CWE-441
Confused Deputy
|
CVE-2026-0098
|
2026-06-3 22:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
7.8 |
HIGH
Local
|
google
|
android
|
In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege wit…
New
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2026-0099
|
2026-06-3 22:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
7.8 |
HIGH
Local
|
google
|
android
|
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0100
|
2026-06-3 22:39 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional e…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-28578
|
2026-06-3 22:35 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-28580
|
2026-06-3 22:35 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
4.0 |
MEDIUM
Local
|
google
|
android
|
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileg…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28581
|
2026-06-3 22:29 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
3.3 |
LOW
Local
|
google
|
android
|
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution pri…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-28586
|
2026-06-3 22:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
8.8 |
HIGH
Network
|
-
|
-
|
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-35085
|
2026-06-3 22:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
8.8 |
HIGH
Network
|
-
|
-
|
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-35084
|
2026-06-3 22:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|