Show filters
793 Total Results
Displaying 51-60 of 793
Sort by:
Attacker Value
Unknown

CVE-2018-9341

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2018-9340

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.
Attacker Value
Unknown

CVE-2018-9338

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13315

Disclosure Date: November 19, 2024 (last updated December 19, 2024)
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13314

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13313

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2017-13311

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13310

Disclosure Date: November 15, 2024 (last updated December 18, 2024)
In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2021-30162

Disclosure Date: April 06, 2021 (last updated February 22, 2025)
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP-210003 (April 2021).
Attacker Value
Unknown

CVE-2020-25281

Disclosure Date: September 11, 2020 (last updated November 28, 2024)
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle unknown-source installations. The LG ID is LVE-SMP-190002 (September 2020).