|
210821
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmw…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2020-0139
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210822
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typ…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0138
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210823
|
7.8 |
HIGH
Local
|
google
|
android
|
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with n…
|
CWE-862
Missing Authorization
|
CVE-2020-0137
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210824
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execu…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-0136
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210825
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privi…
|
CWE-862
Missing Authorization
|
CVE-2020-0135
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210826
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed.…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-0134
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210827
|
7.3 |
HIGH
Local
|
google
|
android
|
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution pr…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-0133
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210828
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional executio…
|
CWE-125 CWE-502
Out-of-bounds Read Deserialization of Untrusted Data
|
CVE-2020-0132
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210829
|
8.8 |
HIGH
Network
|
google
|
android
|
In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges nee…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0131
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210830
|
7.8 |
HIGH
Local
|
google
|
android
|
In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges n…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0129
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|