|
210991
|
7.8 |
HIGH
Local
|
google
|
android
|
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with n…
|
CWE-862
Missing Authorization
|
CVE-2020-0137
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210992
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execu…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-0136
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210993
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privi…
|
CWE-862
Missing Authorization
|
CVE-2020-0135
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210994
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed.…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-0134
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210995
|
7.3 |
HIGH
Local
|
google
|
android
|
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution pr…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-0133
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210996
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional executio…
|
CWE-125 CWE-502
Out-of-bounds Read Deserialization of Untrusted Data
|
CVE-2020-0132
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210997
|
8.8 |
HIGH
Network
|
google
|
android
|
In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges nee…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0131
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210998
|
7.8 |
HIGH
Local
|
google
|
android
|
In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges n…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0129
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210999
|
7.5 |
HIGH
Network
|
google
|
android
|
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2020-0128
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211000
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additiona…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0127
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|