Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.
Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow…
Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allow…
In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege …
In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privil…
In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local…
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This coul…
In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclo…
In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or pe…
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of servi…
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base…
PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files witho…
An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This cou…
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no a…
Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files withou…
In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with…
In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no ad…
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extensio…
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML …
In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper in…
In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper inpu…
In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog d…
In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation.…
In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. …
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.