Show filters
60 Total Results
Displaying 1-10 of 60
Sort by:
Attacker Value
Unknown

CVE-2012-6636

Disclosure Date: March 03, 2014 (last updated October 05, 2023)
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.
1
Attacker Value
Unknown

CVE-2025-20643

Disclosure Date: February 03, 2025 (last updated February 05, 2025)
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.
Attacker Value
Unknown

CVE-2025-20642

Disclosure Date: February 03, 2025 (last updated February 05, 2025)
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2057.
Attacker Value
Unknown

CVE-2025-20641

Disclosure Date: February 03, 2025 (last updated February 05, 2025)
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2058.
Attacker Value
Unknown

CVE-2025-20640

Disclosure Date: February 03, 2025 (last updated February 05, 2025)
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2059.
Attacker Value
Unknown

CVE-2025-20639

Disclosure Date: February 03, 2025 (last updated February 05, 2025)
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2060.
Attacker Value
Unknown

CVE-2025-20638

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291449; Issue ID: MSV-2066.
Attacker Value
Unknown

CVE-2025-20636

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09403554; Issue ID: MSV-2431.
Attacker Value
Unknown

CVE-2025-20635

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09403752; Issue ID: MSV-2434.
Attacker Value
Unknown

CVE-2024-20142

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291406; Issue ID: MSV-2070.