Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages withou…
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch …
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in We…
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…
Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalatio…
In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with Sys…
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of pri…
In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System…
In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additi…
In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution pri…
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with Sys…
In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of privilege with System execution…
In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System …
In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System exe…
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution pri…
In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution pri…
In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additi…
The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pag…
The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload co…
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It …
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a m…
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local …
In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escala…
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local esca…
In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no add…
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local esca…