|
211921
|
7.8 |
HIGH
Local
|
google
|
android
|
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move,…
|
CWE-862
Missing Authorization
|
CVE-2020-0480
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211922
|
7.8 |
HIGH
Local
|
google
|
android
|
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the Document…
|
CWE-863
Incorrect Authorization
|
CVE-2020-0479
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211923
|
7.8 |
HIGH
Local
|
google
|
android
|
In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0478
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211924
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the c…
|
CWE-862
Missing Authorization
|
CVE-2020-0477
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211925
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-0476
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211926
|
7.8 |
HIGH
Local
|
google
|
android
|
In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege wi…
|
CWE-862
Missing Authorization
|
CVE-2020-0475
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211927
|
7.0 |
HIGH
Local
|
google
|
android
|
In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges ne…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-0474
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211928
|
4.6 |
MEDIUM
Physics
|
google
|
android
|
In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical …
|
CWE-863
Incorrect Authorization
|
CVE-2020-0473
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211929
|
3.3 |
LOW
Local
|
google
|
android
|
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execu…
|
CWE-20
Improper Input Validation
|
CVE-2020-0368
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211930
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In nci_proc_ee_management_rsp of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privil…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0280
|
2024-11-21 13:53 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|