Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2024-1609

Disclosure Date: December 25, 2024 (last updated January 05, 2025)
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
0
Attacker Value
Unknown

CVE-2024-1610

Disclosure Date: December 18, 2024 (last updated December 18, 2024)
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
0
Attacker Value
Unknown

CVE-2024-1608

Disclosure Date: February 20, 2024 (last updated February 20, 2024)
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
0
Attacker Value
Unknown

CVE-2023-26311

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
A remote code execution vulnerability in the webview component of OPPO Store app.
Attacker Value
Unknown

CVE-2023-26310

Disclosure Date: August 09, 2023 (last updated September 10, 2024)
There is a command injection problem in the old version of the mobile phone backup app.
Attacker Value
Unknown

CVE-2021-23247

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
Attacker Value
Unknown

CVE-2021-23246

Disclosure Date: March 11, 2022 (last updated October 07, 2023)
In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure.
Attacker Value
Unknown

CVE-2021-23244

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obtain dangerous permission.
Attacker Value
Unknown

CVE-2020-11832

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c have not checked the parameters, which causes a vulnerability.
Attacker Value
Unknown

CVE-2020-11833

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write does not check the parameter len which causes a vulnerability.