
CVE-2014-7224
https://notcve.org/view.php?id=CVE-2014-7224
07 Feb 2020 — A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code. Se presenta una vulnerabilidad de ejecución de código en Android versiones anteriores a 4.4.0, relacionada con el método addJavascriptInterface y los objetos accessibility y accessibilityTraversal, lo que podría permitir a un usuario malicioso remoto ejecutar código arbitrario. • http://www.openwall.com/lists/oss-security/2014/10/02/20 • CWE-20: Improper Input Validation •

CVE-2013-6792 – Google Android - Signature Verification Security Bypass
https://notcve.org/view.php?id=CVE-2013-6792
23 Jan 2020 — Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability Google Android versiones anteriores a 4.4, presenta una Vulnerabilidad de Omisión de Seguridad de Firma APK. • https://www.exploit-db.com/exploits/38821 •

CVE-2016-5346
https://notcve.org/view.php?id=CVE-2016-5346
08 Jan 2020 — An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280). Existe una vulnerabilidad de divulgación de información en el Google Pixel/Pixel SL Qualcomm Avtimer Driver debido a una desreferencia del puntero NULL al procesar una llamada de sistema de aceptación... • http://www.securityfocus.com/bid/97371 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2019-9465
https://notcve.org/view.php?id=CVE-2019-9465
07 Jan 2020 — In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003 En el manejo de operaciones criptográficas de Titan M, hay una posible divulgación de información debido a una causa raíz inusual. Esto podría conllevar a una divulgación de infor... • https://github.com/alexbakker/CVE-2019-9465 •

CVE-2019-9468
https://notcve.org/view.php?id=CVE-2019-9468
06 Jan 2020 — In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471 En la función export_key_der del archivo export_key.cpp, es posible una corrupción de la memoria debido a una doble liberación. Esto podría conllevar a una escalada local de privilegios sin ser necesarios priv... • https://source.android.com/security/bulletin/pixel/2019-12-01 • CWE-415: Double Free CWE-787: Out-of-bounds Write •

CVE-2019-13098
https://notcve.org/view.php?id=CVE-2019-13098
22 Jul 2019 — The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications. La contraseña de usuario por medio del formulario de re... • https://pastebin.com/a5VhaxYn • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-15835 – Android 5.0 Battery Information Broadcast Information Disclosure
https://notcve.org/view.php?id=CVE-2018-15835
13 Nov 2018 — Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983. Android, desde la versión 1.0 hasta la 9.0, tiene permisos inseguros. El ID de error de Android es 77286983. Android OS version 5.0 suffers from a sensitive data exposure vulnerability in its battery information broadcasts. • https://packetstorm.news/files/id/150284 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2018-11304
https://notcve.org/view.php?id=CVE-2018-11304
06 Jul 2018 — Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel. Posible desbordamiento de búfer en msm_adsp_stream_callback_put debido a la falta de validación de entradas de datos proporcionados por el usuario que conduce a un desbordamiento de enteros en todas las distribuciones de Android (Android for MSM, Firefox OS for M... • https://source.android.com/security/bulletin/pixel/2018-07-01#qualcomm-components • CWE-190: Integer Overflow or Wraparound •

CVE-2018-5907
https://notcve.org/view.php?id=CVE-2018-5907
06 Jul 2018 — Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel. Posible desbordamiento de búfer en msm_adsp_stream_callback_put debido a la falta de validación de entradas de datos proporcionados por el usuario que conduce a un desbordamiento de enteros en todas las distribuciones de Android (Android for MSM, Firefox OS for M... • https://source.android.com/security/bulletin/pixel/2018-07-01#qualcomm-components • CWE-190: Integer Overflow or Wraparound •

CVE-2018-6254
https://notcve.org/view.php?id=CVE-2018-6254
10 May 2018 — In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference: N-CVE-2018-6254. En Android antes del nivel de seguridad del 2018-05-05, NVIDIA Media Server contiene una vulnerabilidad de lectura fuera de límites (debido a una validación de entradas incorrecta) que podría desembocar en la divulgación de i... • https://source.android.com/security/bulletin/pixel/2018-05-01 • CWE-125: Out-of-bounds Read CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •