CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-0178

    Last Modified: 21 Nov 2024

    In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local information disclosure of config flags with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143299398

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0185

    Last Modified: 21 Nov 2024

    In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-79945152

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0206

    Last Modified: 21 Nov 2024

    In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of service of the Settings app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136005061

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-0176

    Last Modified: 21 Nov 2024

    In avdt_msg_prs_rej of avdt_msg.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-79702484

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0196

    Last Modified: 21 Nov 2024

    In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144066833

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-0214

    Last Modified: 21 Nov 2024

    In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140292264

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0233

    Last Modified: 21 Nov 2024

    In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150225255

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0143

    Last Modified: 21 Nov 2024

    In nfa_dm_ndef_find_next_handler of nfa_dm_ndef.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of heap data via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145597277

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0150

    Last Modified: 21 Nov 2024

    In rw_t3t_message_set_block_list of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142280329

    Published: 11 Jun 2020
    4.9
    Medium

    CVE-2020-0157

    Last Modified: 21 Nov 2024

    In nfa_hci_conn_cback of nfa_hci_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139740814

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0159

    Last Modified: 21 Nov 2024

    In rw_mfc_writeBlock of rw_mfc.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140768035

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0164

    Last Modified: 21 Nov 2024

    In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736125

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0219

    Last Modified: 21 Nov 2024

    In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-122836081

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-0142

    Last Modified: 21 Nov 2024

    In rw_i93_sm_format of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146435761

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0149

    Last Modified: 21 Nov 2024

    In btu_hcif_mode_change_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142544089

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0156

    Last Modified: 21 Nov 2024

    In NxpNfc::ioctl of NxpNfc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736127

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0177

    Last Modified: 21 Nov 2024

    In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connection settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-126206353

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0139

    Last Modified: 21 Nov 2024

    In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmware. System execution privileges are needed and user interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145520471

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-0140

    Last Modified: 21 Nov 2024

    In rw_i93_sm_detect_ndef of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146053215

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0144

    Last Modified: 21 Nov 2024

    In btm_proc_sp_req_evt of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142543497

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0145

    Last Modified: 21 Nov 2024

    In btm_simple_pair_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142544079

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0146

    Last Modified: 21 Nov 2024

    In btu_hcif_hardware_error_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142546561

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0147

    Last Modified: 21 Nov 2024

    In btu_hcif_esco_connection_chg_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142638392

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0148

    Last Modified: 21 Nov 2024

    In btu_hcif_pin_code_request_evt, btu_hcif_link_key_request_evt, and btu_hcif_link_key_notification_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142638492

    Published: 11 Jun 2020
    6.7
    Medium

    CVE-2020-0153

    Last Modified: 21 Nov 2024

    In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139733543

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0154

    Last Modified: 21 Nov 2024

    In nci_proc_core_rsp of nci_hrcv.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141550919

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0155

    Last Modified: 21 Nov 2024

    In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736386

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0158

    Last Modified: 21 Nov 2024

    In nfc_ncif_proc_t3t_polling_ntf of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141547128

    Published: 11 Jun 2020
    6.7
    Medium

    CVE-2020-0165

    Last Modified: 21 Nov 2024

    In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139532977

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0183

    Last Modified: 21 Nov 2024

    In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-110181479

    Published: 11 Jun 2020
    6.7
    Medium

    CVE-2020-0186

    Last Modified: 21 Nov 2024

    In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146144463

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0188

    Last Modified: 21 Nov 2024

    In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147355897

    Published: 11 Jun 2020
    9.8
    Critical

    CVE-2020-0201

    Last Modified: 21 Nov 2024

    In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143601727

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0202

    Last Modified: 21 Nov 2024

    In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-11 Android ID: A-142936525

    Published: 11 Jun 2020
    7
    High

    CVE-2020-0204

    Last Modified: 21 Nov 2024

    In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS update with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136498130

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0215

    Last Modified: 21 Nov 2024

    In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local escalation of privilege that exposes a pairing Bluetooth MAC address with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1 Android ID: A-140417248

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0216

    Last Modified: 21 Nov 2024

    In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-126204073

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0129

    Last Modified: 21 Nov 2024

    In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123292010

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0136

    Last Modified: 21 Nov 2024

    In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-120078455

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0162

    Last Modified: 21 Nov 2024

    In parseSampleAuxiliaryInformationOffsets of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124526959

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0171

    Last Modified: 21 Nov 2024

    In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127313223

    Published: 11 Jun 2020
    4.1
    Medium

    CVE-2020-0199

    Last Modified: 21 Nov 2024

    In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142142406

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0212

    Last Modified: 21 Nov 2024

    In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-135140854

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0163

    Last Modified: 21 Nov 2024

    In parseSampleAuxiliaryInformationSizes of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124525515

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0170

    Last Modified: 21 Nov 2024

    In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127310810

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0184

    Last Modified: 21 Nov 2024

    In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141688974

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0205

    Last Modified: 21 Nov 2024

    In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147234020

    Published: 11 Jun 2020
    7.3
    High

    CVE-2020-0133

    Last Modified: 21 Nov 2024

    In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145136060

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0137

    Last Modified: 21 Nov 2024

    In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141920289

    Published: 11 Jun 2020
    9.8
    Critical

    CVE-2020-0138

    Last Modified: 21 Nov 2024

    In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142878416

    Published: 11 Jun 2020