In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure w…
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privile…
In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no addi…
In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of pri…
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation …
In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to loca…
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclos…
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local in…
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosur…
In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local informat…
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional exe…
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional exe…
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is S…
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Conte…
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Story Video Editor Co…
An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-…
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content…
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider.…
In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information disclosure with no additiona…
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to loc…
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed…
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution p…
In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local informa…
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One …
**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands …
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPu…