In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could…
In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privile…
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permiss…
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. …
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d…
In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat…
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional …
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera…
In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.
In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with …
In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile…
In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile…
In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosur…
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure wi…
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…
In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additio…
In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote cod…
An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via for…
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe…
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain…
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socke…
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent …