Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dex vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv3
CVE-2017-6415
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file.
Radare Radare2 1.2.1
5.5
CVSSv3
CVE-2017-6387
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote malicious users to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
Radare Radare2 1.2.1
7.5
CVSSv3
CVE-2020-10833
An issue exists on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows malicious users to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).
Google Android 10.0
5.5
CVSSv3
CVE-2018-8808
In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
Radare Radare2 2.4.0
5.5
CVSSv3
CVE-2018-8809
In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
Radare Radare2 2.4.0
6.2
CVSSv3
CVE-2018-21048
An issue exists on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device in Standalone Dex mode. The Samsung ID is SVE-2018-12925 (November 2018).
Google Android 8.0
Google Android 8.1
7.8
CVSSv3
CVE-2017-6319
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote malicious users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
Radare Radare2 1.2.1
3.5
CVSSv3
CVE-2020-13838
An issue exists on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).
Google Android 9.0
Google Android 10.0
7.8
CVSSv3
CVE-2017-6448
The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote malicious users to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.
Radare Radare2 1.2.1
8.4
CVSSv3
CVE-2018-21082
An issue exists on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use screen lock type to unpin" option. The Samsung ID is SVE-2017-11106 (February 2018).
Google Android 7.0
Google Android 7.1.0
Google Android 7.1.1
Google Android 7.1.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »