|
212351
|
7.8 |
HIGH
Local
|
google
|
android
|
In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data wit…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-0486
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212352
|
7.8 |
HIGH
Local
|
google
|
android
|
In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This could lead to local escalation of privilege with no a…
|
CWE-862
Missing Authorization
|
CVE-2020-0485
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212353
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User in…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-0484
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212354
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execut…
|
CWE-416
Use After Free
|
CVE-2020-0483
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212355
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In command of IncidentService.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. Us…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0482
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212356
|
3.3 |
LOW
Local
|
google
|
android
|
In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, w…
|
CWE-863
Incorrect Authorization
|
CVE-2020-0481
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212357
|
7.8 |
HIGH
Local
|
google
|
android
|
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move,…
|
CWE-862
Missing Authorization
|
CVE-2020-0480
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212358
|
7.8 |
HIGH
Local
|
google
|
android
|
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the Document…
|
CWE-863
Incorrect Authorization
|
CVE-2020-0479
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212359
|
7.8 |
HIGH
Local
|
google
|
android
|
In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0478
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212360
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the c…
|
CWE-862
Missing Authorization
|
CVE-2020-0477
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|