Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sagikedmi

#20311of 53,630
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-7886
5.0
2017-05-11
Oneplus · Oxygenos · CVE-2016-10370
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851.
PT-2017-2083
7.6
2017-02-08
Google · Android · CVE-2017-0433
**Name of the Vulnerable Software and Affected Versions** Android versions Kernel-3.10 **Description** An elevation of privilege issue in the Synaptics touchscreen driver could allow a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. **Recommendations** For Android versions Kernel-3.10, at the moment, there is no information about a newer version that contains a fix for this vulnerability.