Lucene search

K

CA Technologies, A Broadcom Company Security Vulnerabilities

osv
osv

Missing RECEIVE_SMS permission in AOSP Bluetooth app

In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

5.5CVSS

5.1AI Score

0.0004EPSS

2021-07-01 12:00 AM
6
osv
osv

[heap-use-after-free in frameworks/av/drm/mediadrm/plugins/clearkey/hidl/DrmPlugin.cpp#590] - ASAN READ

In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7CVSS

7.1AI Score

0.0004EPSS

2021-06-01 12:00 AM
10
osv
osv

App can be made foreground without showing notification to user (even by android system )

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is...

7.8CVSS

7.4AI Score

0.0004EPSS

2021-06-01 12:00 AM
11
osv
osv

Out of bound in avrc_pars_browse_rsp of bluetooth stack

In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for...

6.5CVSS

6.2AI Score

0.001EPSS

2021-06-01 12:00 AM
6
osv
osv

[GWP-ASan] Use after free in bluetooth (sdp)

In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for...

7.5CVSS

7.2AI Score

0.001EPSS

2021-06-01 12:00 AM
6
osv
osv

Memory Disclosure, OOB Write, and Double Free in NFC's Felica Tag Handling

In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for...

8.8CVSS

8.9AI Score

0.001EPSS

2021-05-01 12:00 AM
10
osv
osv

android source bug. in function avrc_msg_cback of avrc_api.cc

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for...

9.8CVSS

9.7AI Score

0.001EPSS

2021-05-01 12:00 AM
9
osv
osv

Android Vomit Report

In tiocspgrp of tty_jobctrl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.9AI Score

0.0005EPSS

2021-05-01 12:00 AM
24
osv
osv

Android Vomit Report

In blkdev_get of block_dev.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

6.7CVSS

7.5AI Score

0.0004EPSS

2021-04-01 12:00 AM
22
osv
osv

[two bugs in android::setPowerModeWithHandle function]

In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-04-01 12:00 AM
11
osv
osv

[Bluetooth information disclosure vulnerability when processing AVCT_CMD of AVRC_OP_SUB_INFO]

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a paired device with no additional execution privileges needed. User interaction is not needed for...

7.5CVSS

7.2AI Score

0.001EPSS

2021-04-01 12:00 AM
11
osv
osv

UAF problem found in wificond

In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-03-01 12:00 AM
3
osv
osv

[Scaning BLE without the location permission using batchscan]

In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not....

7.8CVSS

7.8AI Score

0.0004EPSS

2021-02-01 12:00 AM
9
osv
osv

[NotificationAccessConfirmationActivity could be Overlaid to Trick User Into Making Wrong Choice]

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for...

7.3CVSS

7.3AI Score

0.0004EPSS

2021-02-01 12:00 AM
5
osv
osv

URL hijacking via intent filter in Android OS (first attack)

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-02-01 12:00 AM
7
osv
osv

Apps can get users to unknowingly perform sensitive actions using custom activity transitions

In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...

7.8CVSS

7.5AI Score

0.0005EPSS

2021-02-01 12:00 AM
29
osv
osv

Activity overlay attacks with FLAG_NOT_TOUCHABLE, FLAG_WATCH_OUTSIDE_TOUCH and android:windowIsTranslucent

In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for...

7.8CVSS

8AI Score

0.0005EPSS

2021-02-01 12:00 AM
5
osv
osv

Potential vulnerability in Java TLS Hostname Verification

In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for...

7.5CVSS

7AI Score

0.001EPSS

2021-02-01 12:00 AM
4
github
github

Symfony has a security issue when parsing the Authorization header

All 2.0.X, 2.1.X, 2.2.X, 2.3.X, 2.4.X, and 2.5.X versions of the Symfony HttpFoundation component are affected by this security issue. This issue has been fixed in Symfony 2.3.19, 2.4.9, and 2.5.4. Note that no fixes are provided for Symfony 2.0, 2.1, and 2.2 as they are not maintained anymore....

6.8AI Score

EPSS

2024-05-30 12:41 AM
2
osv
osv

App can get access to all slice providers installed on the device without requiring any permission.

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-05-01 12:00 AM
5
osv
osv

INSTALL_DONT_KILL_APP can be used to force a mismatch between running code and a parsed APK

In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7AI Score

0.0004EPSS

2022-05-01 12:00 AM
3
osv
osv

Surface level lock screen bypass with complete file system access

In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.4AI Score

0.0004EPSS

2022-05-01 12:00 AM
9
osv
osv

SystemUI unwraps PendingIntent through getIntent() allowing launching OngoingCallController arbitrary Activities via

In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.1AI Score

0.0004EPSS

2022-05-01 12:00 AM
2
osv
osv

net/packet: rx_owner_map depends on pg_vec

In packet_set_ring of af_packet.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...

7CVSS

7.1AI Score

0.001EPSS

2022-05-01 12:00 AM
8
osv
osv

[GKI] Revert mprotect optimization from android12-5.10 branch

In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.1AI Score

0.0004EPSS

2022-04-01 12:00 AM
6
osv
osv

[Crafted GATT Notification Request Packet Causes Out-of-bounds Read/Write in Bluetooth]

In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

9.8CVSS

7.2AI Score

0.001EPSS

2022-03-01 12:00 AM
6
osv
osv

binder SELinux checks are racy wrt concurrent execve()

In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7CVSS

6.8AI Score

0.0004EPSS

2022-03-01 12:00 AM
5
osv
osv

[EoP: Bypass Storage Restriction in Android 11]

In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-03-01 12:00 AM
2
osv
osv

Set Credential Manager App without User Consent

In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for...

7.8CVSS

7.8AI Score

0.0005EPSS

2022-03-01 12:00 AM
6
osv
osv

PendingIntent hijack vulnerability in SipAccountRegistry.java

In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.1AI Score

0.0004EPSS

2022-03-01 12:00 AM
4
osv
osv

[Android Auto] App permissions reset after upgrade on device from R build to S build

In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-03-01 12:00 AM
8
osv
osv

Android Vomit Report

In __split_huge_pmd of huge_memory.c, there is a possible incorrectly mapped page due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7CVSS

6.8AI Score

0.001EPSS

2022-03-01 12:00 AM
8
osv
osv

[OOB problem found in media.metrics process]

In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

5.5CVSS

5.1AI Score

0.0004EPSS

2022-02-01 12:00 AM
4
osv
osv

EoP: non system overlay on InstallCaCertificateWarning

In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...

7.8CVSS

7.8AI Score

0.0005EPSS

2022-02-01 12:00 AM
9
osv
osv

nfc_integration_fuzzer: Tag-mismatch in NFA_SendRawFrame

In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

9.8CVSS

9.5AI Score

0.001EPSS

2022-02-01 12:00 AM
15
osv
osv

Crash in /system/bin/servicemanager, HWAddressSanitizer: tag-mismatch on address 0x0047d0091f80 at pc 0x0070cd6a11e4 READ of size 8 at 0x0047d0091f80 tags: d3/5b (ptr/mem) in thread T0

In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-01-01 12:00 AM
7
osv
osv

Dialer launchVoicemailSettingsIntent PendingIntent could be Hijacked to Access of Sensitive Contacts and ICCID

In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-01-01 12:00 AM
8
osv
osv

[SIGSEGV in /system/lib64/libstagefright.so (android::SimpleDecodingSource::doRead)]

In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

9.8CVSS

9.4AI Score

0.001EPSS

2022-01-01 12:00 AM
4
osv
osv

callVoicemailPendingIntent could be Hijacked to Access Contacts

In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-01-01 12:00 AM
8
osv
osv

[Security Issue] Inconsistent Root Permission Check for Fabricated Overlays

In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.6AI Score

0.0004EPSS

2022-01-01 12:00 AM
5
osv
osv

BUG: unable to handle kernel paging request in csum_partial

In gre_handle_offloads of ip_gre.c, there is a possible page fault due to an invalid memory access. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

5.5CVSS

5.8AI Score

0.0004EPSS

2022-01-01 12:00 AM
16
osv
osv

[Security] Linux kernel vulnerability advisory

fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka...

7.8CVSS

8AI Score

0.002EPSS

2021-12-01 12:00 AM
22
osv
osv

[Phone] Secretly pair a remote Bluetooth device without user consent

In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

8.8CVSS

8.5AI Score

0.0005EPSS

2021-12-01 12:00 AM
4
osv
osv

App can stop vpn profile of other apps and can reset always on vpn package without requiring any permission.

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-11-01 12:00 AM
8
osv
osv

Phishing attacks over Bluetooth due to unclear warning message

In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional...

7.3CVSS

6.9AI Score

0.0004EPSS

2021-11-01 12:00 AM
5
osv
osv

midi_extractor_fuzzer: Global-buffer-overflow in WT_InterpolateNoLoop

In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for...

6.5CVSS

6.2AI Score

0.001EPSS

2021-11-01 12:00 AM
8
osv
osv

[Sensitive SubScriber ID could be Stolen via Intercepting SnoozeWarningIntent and SnoozeRapidIntent in NetworkPolicyManagerService]

In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

5.5CVSS

4.8AI Score

0.0004EPSS

2021-11-01 12:00 AM
8
osv
osv

[startActivity() with system privileges]

In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-11-01 12:00 AM
7
osv
osv

EoP in PackageManager

In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-11-01 12:00 AM
8
osv
osv

KASAN: slab-out-of-bounds in xhci_vendor_get_ops when launching android12-5.10 in Cuttlefish

In xhci_vendor_get_ops of xhci.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

7.8CVSS

7.3AI Score

0.0004EPSS

2021-11-01 12:00 AM
12
Total number of security vulnerabilities2915242