In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local in…
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local in…
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local in…
In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to l…
In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local in…
In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local informati…
In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission ch…
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User executi…
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of p…
In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation…
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone …
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no ad…
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disc…
In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing…
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, a…
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the g…
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission che…
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permissi…
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a m…
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logge…
Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly …
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of…
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowi…
A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…
A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an atta…
A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the exis…
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Ove…
A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain …