Show filters
782 Total Results
Displaying 71-80 of 782
Sort by:
Attacker Value
Unknown

CVE-2017-13313

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2017-13312

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13311

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13310

Disclosure Date: November 15, 2024 (last updated December 18, 2024)
In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13227

Disclosure Date: November 14, 2024 (last updated November 20, 2024)
In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2021-25480

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.
Attacker Value
Unknown

CVE-2021-25382

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
Attacker Value
Unknown

CVE-2021-30162

Disclosure Date: April 06, 2021 (last updated February 22, 2025)
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP-210003 (April 2021).
Attacker Value
Unknown

CVE-2021-25369

Disclosure Date: March 26, 2021 (last updated February 22, 2025)
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Attacker Value
Unknown

CVE-2021-25370

Disclosure Date: March 26, 2021 (last updated February 22, 2025)
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.