In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in …
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …
In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of pr…
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …
In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …
In memory management driver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege wit…
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with…
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no …
In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no …
In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no add…
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution wit…
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC wi…
In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution ove…
In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could l…
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could …
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could le…
In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This co…
In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/ove…
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information …
In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with …
In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privil…
In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclos…
In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local informa…
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local inform…
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity wi…
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary fi…
Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an esc…
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel…