In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additi…
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no addi…
In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local information disclosure with no …
In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional exe…
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution pri…
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution pri…
In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information dis…
In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure w…
In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with U…
In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional ex…
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system pr…
In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with …
In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to l…
In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional…
In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of pr…
In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege …
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escala…
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation…
In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution priv…
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalati…
In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This …
In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege…
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalati…
In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and g…
In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local inform…
In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to lo…
In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure…
In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead t…
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This coul…
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-149871374