CWE-927

Total CVEs
16
Vulnerabilities
Avg CVSS v3
4.9
Medium
Avg CVSS v2
5.1
Medium
Latest CVE
2024
Most Recent

Severity Distribution

Critical 0
0%
High 2
12.5%
Medium 9
56.3%
Low 5
31.3%

External References

All CVEs (16)

Page 1 of 1
CVSS:8.1(High)

A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. I...

CVSS:7.8(High)

The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideA...

CVSS:5.5(Medium)

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization.

CVSS:5.5(Medium)

he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same devic...

CVSS:5.5(Medium)

PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVSS:5.5(Medium)

PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVSS:5.5(Medium)

Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVSS:5.1(Medium)

A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permissio...

CVSS:5.0(Medium)

An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices.

CVSS:4.8(Medium)

NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer componen...

CVSS:4.4(Medium)

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.

CVSS:3.3(Low)

The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceF...

CVSS:3.3(Low)

Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVSS:2.8(Low)

An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.

CVSS:2.8(Low)

An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.

CVSS:2.8(Low)

An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.