Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2020-11835

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_write in proc_work_mode_write causes a vulnerability.
Attacker Value
Unknown

CVE-2020-11834

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not check the parameter len, resulting in a vulnerability.
Attacker Value
Unknown

CVE-2020-11830

Disclosure Date: November 19, 2020 (last updated November 28, 2024)
QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.
Attacker Value
Unknown

CVE-2020-11829

Disclosure Date: November 19, 2020 (last updated November 28, 2024)
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722.
Attacker Value
Unknown

CVE-2020-11831

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.
Attacker Value
Unknown

CVE-2020-11828

Disclosure Date: April 21, 2020 (last updated February 21, 2025)
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is returned to the attackers, leading to values on the stack information leakage, the vulnerability can be used to bypass attackers ALSR.
Attacker Value
Unknown

CVE-2018-14996

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-installed platform app with a package name of com.dropboxchmod (versionCode=1, versionName=1.0) that contains an exported service named com.dropboxchmod.DropboxChmodService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. This vulnerability can also be used to secretly record audio of the user without their awareness on the Oppo F5 device. The pre-installed com.oppo.engineermode app (versionCode=25, versionName=V1.01) has an …
0
Attacker Value
Unknown

CVE-2010-4942

Disclosure Date: October 09, 2011 (last updated October 04, 2023)
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the lid parameter.
0
Attacker Value
Unknown

CVE-2010-3467

Disclosure Date: September 17, 2010 (last updated October 04, 2023)
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.
0
Attacker Value
Unknown

CVE-2006-5978

Disclosure Date: November 20, 2006 (last updated October 04, 2023)
Unspecified vulnerability in E-Xoopport before 2.2.0 has unknown impact and attack vectors, as addressed by "Some security fix."
0