Lucene search

K

Android OS Security Vulnerabilities

cve
cve

CVE-2020-25282

An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September...

9.8CVSS

9.1AI Score

0.001EPSS

2020-09-11 10:15 PM
24
cve
cve

CVE-2020-25283

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September...

9.8CVSS

9.1AI Score

0.001EPSS

2020-09-11 10:15 PM
18
cve
cve

CVE-2020-25281

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle unknown-source installations. The LG ID is LVE-SMP-190002 (September...

7.5CVSS

7.5AI Score

0.001EPSS

2020-09-11 10:15 PM
18
cve
cve

CVE-2020-25062

An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July...

9.8CVSS

9.2AI Score

0.001EPSS

2020-08-31 09:15 PM
23
cve
cve

CVE-2020-25059

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A service crash may occur because of incorrect input validation. The LG ID is LVE-SMP-200013 (July...

7.5CVSS

7.5AI Score

0.001EPSS

2020-08-31 09:15 PM
21
cve
cve

CVE-2020-25060

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July...

7.8CVSS

7.7AI Score

0.0004EPSS

2020-08-31 09:15 PM
26
cve
cve

CVE-2020-25063

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect application-level input validation. The LG ID is LVE-SMP-200018 (July...

7.5CVSS

7.5AI Score

0.001EPSS

2020-08-31 09:15 PM
21
cve
cve

CVE-2020-25065

An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August...

7.5CVSS

7.5AI Score

0.001EPSS

2020-08-31 09:15 PM
24
cve
cve

CVE-2020-25061

An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July...

9.8CVSS

9.2AI Score

0.001EPSS

2020-08-31 09:15 PM
23
cve
cve

CVE-2020-25064

An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Certain automated testing is mishandled. The LG ID is LVE-SMP-200019 (August...

7.5CVSS

7.5AI Score

0.001EPSS

2020-08-31 09:15 PM
29
cve
cve

CVE-2020-25058

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July...

9.8CVSS

9.2AI Score

0.001EPSS

2020-08-31 09:15 PM
25
cve
cve

CVE-2020-25057

An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK installations. The LG ID is LVE-SMP-200011 (July...

9.8CVSS

9.2AI Score

0.001EPSS

2020-08-31 09:15 PM
16
cve
cve

CVE-2020-0204

In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS update with no additional execution privileges...

7CVSS

7.5AI Score

0.0004EPSS

2020-06-11 03:15 PM
21
cve
cve

CVE-2020-13842

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June...

7.8CVSS

7.7AI Score

0.0004EPSS

2020-06-05 12:15 AM
65
cve
cve

CVE-2020-13843

An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June...

5.5CVSS

5.5AI Score

0.0004EPSS

2020-06-05 12:15 AM
60
cve
cve

CVE-2020-13839

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June...

9.8CVSS

9.5AI Score

0.002EPSS

2020-06-05 12:15 AM
63
cve
cve

CVE-2020-13840

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June...

9.8CVSS

9.6AI Score

0.002EPSS

2020-06-05 12:15 AM
64
cve
cve

CVE-2020-13841

An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended access restrictions. The LG ID is LVE-SMP-200009 (June...

9.8CVSS

9.3AI Score

0.001EPSS

2020-06-05 12:15 AM
59
cve
cve

CVE-2020-12753

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May...

9.8CVSS

9.5AI Score

0.016EPSS

2020-05-11 04:15 PM
41
cve
cve

CVE-2020-12754

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application can obtain control of device input via the window system service. The LG ID is LVE-SMP-170011 (May...

7.8CVSS

7.5AI Score

0.0005EPSS

2020-05-11 04:15 PM
24
cve
cve

CVE-2020-6616

Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8....

6.5CVSS

7.5AI Score

0.001EPSS

2020-05-08 08:15 PM
169
cve
cve

CVE-2020-8899

There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram image codec leading.....

9.8CVSS

9.7AI Score

0.034EPSS

2020-05-06 05:15 PM
103
4
cve
cve

CVE-2020-11873

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer overflow in the logging tool could allow an attacker to gain privileges. The LG ID is LVE-SMP-200005 (April...

9.8CVSS

9.5AI Score

0.001EPSS

2020-04-17 02:15 PM
30
cve
cve

CVE-2020-11875

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-200001 (February...

7.8CVSS

7.6AI Score

0.0004EPSS

2020-04-17 02:15 PM
40
4
cve
cve

CVE-2020-11874

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory Reset Protection (FRP). The LG ID is LVE-SMP-200004 (March...

7.5CVSS

7.5AI Score

0.001EPSS

2020-04-17 02:15 PM
23
cve
cve

CVE-2019-20785

An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January...

6.8CVSS

6.6AI Score

0.0005EPSS

2020-04-17 02:15 PM
28
cve
cve

CVE-2019-20784

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Interaction of GPS with 911 emergency calls is mishandled. The LG ID is LVE-SMP-180012 (January...

5.5CVSS

5.6AI Score

0.0004EPSS

2020-04-17 02:15 PM
26
cve
cve

CVE-2019-20783

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (North America CDMA) software. The LTE protocol implementation allows a bypass of AKA (Authentication and Key Agreement). The LG ID is LVE-SMP-180014 (February...

9.1CVSS

9AI Score

0.001EPSS

2020-04-17 02:15 PM
22
cve
cve

CVE-2019-20779

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A TrustZone trusted application can crash via crafted input. The LG ID is LVE-SMP-190003 (May...

5.5CVSS

5.5AI Score

0.0004EPSS

2020-04-17 02:15 PM
25
cve
cve

CVE-2019-20778

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Backup subsystem does not properly restrict operations or validate their input. The LG ID is LVE-SMP-190004 (June...

9.8CVSS

9.2AI Score

0.001EPSS

2020-04-17 02:15 PM
24
cve
cve

CVE-2019-20780

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April...

9.8CVSS

9.2AI Score

0.001EPSS

2020-04-17 02:15 PM
25
cve
cve

CVE-2019-20782

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. LG Advanced Flash (LAF) has a buffer overflow. The LG ID is LVE-SMP-190001 (March...

9.8CVSS

9.4AI Score

0.001EPSS

2020-04-17 02:15 PM
23
cve
cve

CVE-2019-20776

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. A TZ trusted application can crash via crafted input. The LG ID is LVE-SMP-190005 (July...

5.5CVSS

5.5AI Score

0.0004EPSS

2020-04-17 02:15 PM
26
cve
cve

CVE-2019-20777

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService mishandles OTA Provisioning on V40 and G7 devices. The LG ID is LVE-SMP-190006 (July...

9.8CVSS

9.2AI Score

0.001EPSS

2020-04-17 02:15 PM
28
cve
cve

CVE-2019-20773

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August...

7.8CVSS

7.8AI Score

0.0004EPSS

2020-04-17 02:15 PM
21
cve
cve

CVE-2019-20775

An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August...

5.5CVSS

5.2AI Score

0.0004EPSS

2020-04-17 02:15 PM
21
cve
cve

CVE-2019-20774

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August...

5.5CVSS

5.5AI Score

0.0004EPSS

2020-04-17 02:15 PM
24
cve
cve

CVE-2019-20771

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService allows unconfirmed configuration changes via a modified OMACP message. The LG ID is LVE-SMP-190006 (August...

7.5CVSS

7.4AI Score

0.001EPSS

2020-04-17 02:15 PM
35
cve
cve

CVE-2019-20770

An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buffer overflow that leads to arbitrary code execution. The LG ID is LVE-SMP-190013 (September...

7.8CVSS

8AI Score

0.0004EPSS

2020-04-17 02:15 PM
31
cve
cve

CVE-2019-20772

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August...

9.8CVSS

9.2AI Score

0.001EPSS

2020-04-17 02:15 PM
31
cve
cve

CVE-2020-6381

Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

8.8CVSS

8.4AI Score

0.006EPSS

2020-02-11 03:15 PM
229
cve
cve

CVE-2019-11516

An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Extended Inquiry Responses (EIRs) are improperly handled, which causes a heap-based buffer overflow during device inquiry. This overflow can be used to overwrite existing functions....

8.1CVSS

8.2AI Score

0.002EPSS

2020-02-05 05:15 PM
26
cve
cve

CVE-2019-8792

An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code...

8.8CVSS

8AI Score

0.004EPSS

2019-12-18 06:15 PM
20
15
cve
cve

CVE-2019-19464

The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted...

5.3CVSS

5.1AI Score

0.001EPSS

2019-11-30 02:15 AM
19
cve
cve

CVE-2019-14319

The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network...

6.5CVSS

6AI Score

0.002EPSS

2019-09-04 08:15 PM
102
cve
cve

CVE-2019-9506

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary...

8.1CVSS

8.8AI Score

0.001EPSS

2019-08-14 05:15 PM
403
3
cve
cve

CVE-2019-5679

NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalation of privileges, and information disclosure, code execution, denial of...

7.8CVSS

7.8AI Score

0.0004EPSS

2019-08-06 08:15 PM
40
cve
cve

CVE-2018-12010

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check may lead to possible stack overflow resulting in memory corruption in trustzone...

7.8CVSS

7.8AI Score

0.0004EPSS

2019-02-11 03:29 PM
18
cve
cve

CVE-2018-12011

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information...

5.5CVSS

5.2AI Score

0.0004EPSS

2019-02-11 03:29 PM
20
cve
cve

CVE-2018-11962

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Use-after-free issue in heap while loading audio effects config in audio effects...

7.8CVSS

5.9AI Score

0.0004EPSS

2019-02-11 03:29 PM
19
Total number of security vulnerabilities993