Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Coloros Assistant CRITICAL 9.8
CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Mitigation only
Fix from $2,300 2026-04-30
Usercenter Credit Software Development Kit HIGH 7.5
CVE-2024-1608

In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal info…

Mitigation only
Fix from $1,950 2024-02-20
Oppo Store CRITICAL 9.8
CVE-2023-26311

A remote code execution vulnerability in the webview component of OPPO Store app.

No fix yet
Fix from $2,300 2023-08-10
Coloros CRITICAL 9.8
CVE-2023-26310

There is a command injection problem in the old version of the mobile phone backup app.

No fix yet
Fix from $2,300 2023-08-09
Quick App CRITICAL 9.8
CVE-2021-23247

A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary cod…

No fix yet
Fix from $2,300 2022-04-01
Coloros HIGH 7.5
CVE-2021-23246

In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure.

Mitigation only
Fix from $1,950 2022-03-11
Coloros HIGH 7.8
CVE-2021-23244

ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not …

Mitigation only
Fix from $1,950 2021-12-27
Reno3 Pro Firmware MEDIUM 5.5
CVE-2020-11832

In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c have not …

No fix yet
Fix from $1,600 2020-12-31
Reno3 Pro Firmware MEDIUM 5.5
CVE-2020-11833

In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write does not c…

No fix yet
Fix from $1,600 2020-12-31
Reno3 Pro Firmware MEDIUM 5.5
CVE-2020-11834

In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not …

No fix yet
Fix from $1,600 2020-12-31
Reno3 Pro Firmware MEDIUM 5.5
CVE-2020-11835

In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_writ…

No fix yet
Fix from $1,600 2020-12-31
Coloros CRITICAL 9.8
CVE-2020-11829

Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_20072…

Mitigation only
Fix from $2,300 2020-11-19
Qualityprotect CRITICAL 9.8
CVE-2020-11830

QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.

Mitigation only
Fix from $2,300 2020-11-19
Ovoicemanager CRITICAL 9.8
CVE-2020-11831

OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.

Mitigation only
Fix from $2,300 2020-11-19
Coloros HIGH 7.5
CVE-2020-11828

In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is def…

Mitigation only
Fix from $1,950 2020-04-21
F5 Firmware HIGH 7.8
CVE-2018-14996

The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-installed platfo…

Mitigation only
Fix from $1,950 2019-04-25