| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption in WLAN while running doDriverCmd for an unspecific command. |
| Memory corruption in RIL while trying to send apdu packet. |
| Information disclosure in Bluetooth when an GATT packet is received due to improper input validation. |
| Memory corruption due to untrusted pointer dereference in automotive during system call. |
| Memory corruption in Trusted Execution Environment while calling service API with invalid address. |
| Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. |
| Information disclosure in Network Services due to buffer over-read while the device receives DNS response. |
| User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for
SQL injections. |
| User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for
arbitrary code execution. |
| User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for
arbitrary code execution. |
|
Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator
credentials allowing the configuration of the application.
|
|
Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials
that are used in the integration interface towards 3rd party systems.
|
|
A broken access control was found allowing for privileged escalation of the operator account to gain
administrator privileges. |
| In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
|
| In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
|
| In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
|
| In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
|
| In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
|
| In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
|
| In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
|