CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability. |
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. |
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability. |
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files. |
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background. |
The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. |
The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. |
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation. |
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation. |
The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings. |
The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background. |
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality. |
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation. |
Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality. |
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality. |
AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability. |
The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. |
The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect data confidentiality. |
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality. |
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. |