
CVE-2020-13840
https://notcve.org/view.php?id=CVE-2020-13840
04 Jun 2020 — An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020). Se detectó un problema en los dispositivos móviles LG con Sistema Operativo Android versiones 7.2, 8.0, 8.1, 9 y 10 (chipsets MTK). Una ejecución de código puede ocurrir por medio de un desbordamiento del búfer del manejador de comando MTK AT. • https://lgsecurity.lge.com • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-13839
https://notcve.org/view.php?id=CVE-2020-13839
04 Jun 2020 — An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020). Se detectó un problema en los dispositivos móviles LG con Sistema Operativo Android versiones 7.2, 8.0, 8.1, 9 y 10 (chipsets MTK). Una ejecución del código puede ocurrir por medio de un desbordamiento del búfer del manejador de comando AT personalizado. • https://lgsecurity.lge.com • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-13831
https://notcve.org/view.php?id=CVE-2020-13831
04 Jun 2020 — An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020). Se detectó un problema en los dispositivos móviles Samsung con versiones de software O(8.x) y P(9.0) (chipsets Exynos 7570). El componente Trustonic Kinibi permite una asignación de memoria arbitraria. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2020-13833
https://notcve.org/view.php?id=CVE-2020-13833
04 Jun 2020 — An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020). Se detectó un problema en los dispositivos móviles Samsung con versiones de software O(8.x), P(9.0) y Q(10.0). El área del sistema permite sobrescrituras arbitrarias de archivos por medio de un ataque de tipo symlink. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2020-13834
https://notcve.org/view.php?id=CVE-2020-13834
04 Jun 2020 — An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict use of Android Debug Bridge (adb) for arbitrary installations. The Samsung ID is SVE-2020-17369 (June 2020). Se detectó un problema en los dispositivos móviles Samsung con versiones de software O(8.x), P(9.0) y Q(10.0) (con TEEGRIS). Secure Folder no restringe apropiadamente el uso de Android Debug Bridge (adb) para instalaciones arbitrarias. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-863: Incorrect Authorization •

CVE-2020-13835
https://notcve.org/view.php?id=CVE-2020-13835
04 Jun 2020 — An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020). Se detectó un problema en los dispositivos móviles Samsung con versión de software O(8.x) (con TEEGRIS). El Gatekeeper Trustlet permite un ataque de fuerza bruta sobre las credenciales del usuario. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-20: Improper Input Validation CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVE-2020-13836
https://notcve.org/view.php?id=CVE-2020-13836
04 Jun 2020 — An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020). Se detectó un problema en los dispositivos móviles Samsung con versiones de software O(8.x), P(9.0) y Q(10.0). HWRResProvider permite un Salto de Ruta para una exposición de datos. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-0100
https://notcve.org/view.php?id=CVE-2020-0100
14 May 2020 — In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to local information disclosure of data from a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-8.0Android ID: A-150156584 En la función onTransact del archivo IHDCP.cpp, se presenta una posible lectura fuera de límites debido al manejo incorrecto de errores. Esto podría conllevar a ... • https://source.android.com/security/bulletin/2020-05-01 • CWE-125: Out-of-bounds Read •

CVE-2020-0093 – libexif: out of bounds read due to a missing bounds check in exif_data_save_data_entry function in exif-data.c
https://notcve.org/view.php?id=CVE-2020-0093
14 May 2020 — In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132 En la función exif_data_save_data_entry del archivo exif-data.c, se presenta una posible lectura fuera de límites debido a una falta de comprobación de límites. Es... • http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html • CWE-125: Out-of-bounds Read •

CVE-2020-0096
https://notcve.org/view.php?id=CVE-2020-0096
14 May 2020 — In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-145669109 En la función startActivities del archivo ActivityStartController.java, se presenta una posible escalada de privilegios debido a un problema de tipo confused depu... • https://github.com/tea9/CVE-2020-0096-StrandHogg2 •