|
210831
|
7.5 |
HIGH
Network
|
google
|
android
|
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2020-0128
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210832
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additiona…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0127
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210833
|
6.4 |
MEDIUM
Local
|
google
|
android
|
In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with System execution privileges required. User interaction…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-0126
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210834
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privile…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0124
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210835
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privilege…
|
NVD-CWE-noinfo
|
CVE-2020-0121
|
2024-11-21 13:52 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210836
|
5.3 |
MEDIUM
Network
|
google
|
android
|
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote informati…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-0119
|
2024-11-21 13:52 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210837
|
7.8 |
HIGH
Local
|
google
|
android
|
In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution pri…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-0118
|
2024-11-21 13:52 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210838
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privilege…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-0117
|
2024-11-21 13:52 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210839
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass. This could lead to local information disclosure with no ad…
|
NVD-CWE-noinfo
|
CVE-2020-0116
|
2024-11-21 13:52 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210840
|
7.8 |
HIGH
Local
|
google
|
android
|
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalat…
|
CWE-863
Incorrect Authorization
|
CVE-2020-0115
|
2024-11-21 13:52 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|