Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2018-9372 In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escal… Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.8 CVE-2018-9409 In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local e… Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.5 CVE-2018-9364 In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User i… Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.3 CVE-2018-9369 In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.3 CVE-2018-9370 In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check.… Android Mitigation only Fix from $1,9502024-11-19 MEDIUM 6.5 CVE-2018-9348 In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with… Android Mitigation only Fix from $1,6002024-11-19 MEDIUM 6.4 CVE-2018-9371 In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with … Android Mitigation only Fix from $1,6002024-11-19 MEDIUM 5.5 CVE-2018-9346 In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead … Android Patch available Fix from $1,6002024-11-19 HIGH 7.8 CVE-2018-9339 In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to l… Android Patch available Fix from $1,9502024-11-19 HIGH 7.8 CVE-2018-9341 In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary cod… Android Patch available Fix from $1,9502024-11-19 HIGH 7.8 CVE-2018-9344 In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privi… Android Patch available Fix from $1,9502024-11-19 MEDIUM 5.5 CVE-2018-9340 In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing info… Android Patch available Fix from $1,6002024-11-19 MEDIUM 5.5 CVE-2018-9345 In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead … Android Patch available Fix from $1,6002024-11-19 HIGH 7.8 CVE-2023-21270 In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to … Android Patch available Fix from $1,9502024-11-19 HIGH 7.8 CVE-2017-13315 In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevati… Android Patch available Fix from $1,9502024-11-19 HIGH 7.8 CVE-2018-9338 In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalat… Android Mitigation only Fix from $1,9502024-11-19 MEDIUM 6.1 CVE-2024-11023 Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session sy… Firebase Javascript Sdk 10.9.0+ Fix from $1,6002024-11-18 HIGH 7.8 CVE-2017-13310 In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local e… Android Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2017-13312 In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escal… Android Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2017-13314 In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul… Android Patch available Fix from $1,9502024-11-15 MEDIUM 6.7 CVE-2017-13311 In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to l… Android Mitigation only Fix from $1,6002024-11-15 MEDIUM 6.5 CVE-2017-13313 In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an inco… Android Patch available Fix from $1,6002024-11-15 MEDIUM 5.5 CVE-2017-13309 In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information … Android Mitigation only Fix from $1,6002024-11-15 MEDIUM 5.5 CVE-2017-13227 In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure … Android Patch available Fix from $1,6002024-11-14 CRITICAL 9.8 CVE-2024-43091 In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution… Android Patch available Fix from $2,3002024-11-13 HIGH 7.8 CVE-2024-43085 In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic … Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43087 In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the access… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43088 In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due … Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43089 In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc… Android Patch available Fix from $1,9502024-11-13 HIGH 7.3 CVE-2024-43093 KEV In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive direc… Android Patch available Fix from $1,9502024-11-13