|
212431
|
7.5 |
HIGH
Network
|
google
|
android
|
In rw_i93_sm_format of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges nee…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0142
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212432
|
4.4 |
MEDIUM
Network
|
google
|
android
|
In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a race condition. This could lead to remote information disclosure with System execution privileges nee…
|
CWE-362
Race Condition
|
CVE-2020-0141
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212433
|
7.5 |
HIGH
Network
|
google
|
android
|
In rw_i93_sm_detect_ndef of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privilege…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0140
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212434
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmw…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2020-0139
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212435
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typ…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0138
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212436
|
7.8 |
HIGH
Local
|
google
|
android
|
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with n…
|
CWE-862
Missing Authorization
|
CVE-2020-0137
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212437
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execu…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-0136
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212438
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privi…
|
CWE-862
Missing Authorization
|
CVE-2020-0135
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212439
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed.…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-0134
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212440
|
7.3 |
HIGH
Local
|
google
|
android
|
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution pr…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-0133
|
2024-11-21 13:52 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|