Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
android vulnerabilities and exploits
(subscribe to this query)
10
CVSSv3
CVE-2021-25387
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows malicious users to execute arbitrary code on mediaextractor process.
Google Android 8.1
Google Android 9.0
Google Android 10.0
Google Android 11.0
10
CVSSv3
CVE-2018-6968
The VMware AirWatch Agent for Android before 8.2 and AirWatch Agent for Windows Mobile before 6.5.2 contain a remote code execution vulnerability in real time File Manager capabilities. This vulnerability may allow for unauthorized creation and execution of files in the Agent san...
Vmware Airwatch Agent
1 Article
9.9
CVSSv3
CVE-2021-1411
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an malicious user to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept pro...
Cisco Jabber
1 Article
9.8
CVSSv3
CVE-2024-20011
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.
Google Android 11.0
Google Android 12.0
Google Android 13.0
9.8
CVSSv3
CVE-2023-47883
The com.altamirano.fabricio.tvbrowser TV browser application up to and including 4.5.1 for Android is vulnerable to JavaScript code execution via an explicit intent due to an exposed MainActivity.
Vladymix Tv Browser
9.8
CVSSv3
CVE-2023-43955
The com.phlox.tvwebbrowser TV Bro application up to and including 2.0.0 for Android mishandles external intents through WebView. This allows malicious users to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloa...
Fedirtsapana Tv Bro
9.8
CVSSv3
CVE-2023-49583
SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Sap \\@sap\\/xssec
1 Article
9.8
CVSSv3
CVE-2023-50422
SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to prior to 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacke...
Sap Cloud-security-services-integration-library
1 Article
9.8
CVSSv3
CVE-2023-48423
In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Google Android -
9.8
CVSSv3
CVE-2023-40078
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed...
Google Android 14.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3400
CVE-2023-7252
CVE-2024-21111
denial of service
CVE-2024-29661
CVE-2024-22856
remote attackers
encryption
CVE-2023-38299
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »