The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
78 vulnerabilities with CWE-926
CVE-2024-13916
MEDIUM
Kruger&Matz com.pri.applock 13 - Unauthenticated PIN Code Exfiltration via Exported Content Provider
CVE-2024-13915
MEDIUM
Ulefone and Krger&Matz com.pri.factorytest < 1.0 - Unauthenticated Factory Reset via Exported Service
CVE-2024-36437
MEDIUM
TextNow <24.17.0.2 - Code Injection
CVSS 6.5
CVE-2024-6051
MEDIUM
Vercom S.A. Redlink SDK <1.13 - XSS
CVE-2024-3479
LOW
Motorola Enterprise MotoDpms Provider - Info Disclosure
CVSS 2.8
CVE-2024-27086
LOW
Microsoft.Identity.Client 4.48.0-4.60.0 - Local Denial of Service via Activity Export Misconfiguration
CVSS 3.9
CVE-2023-41823
MEDIUM
Motorola Phone Extension - Code Injection
CVSS 4.4
CVE-2023-41822
MEDIUM
Motorola Interface Test Tool - Command Injection
CVSS 4.8
CVE-2023-41821
MEDIUM
Motorola Phones < 2023-09-01 - Sensitive User Information Exposure via Setup Application
CVSS 5.0
CVE-2023-41816
MEDIUM
Motorola Services Main - Info Disclosure
CVSS 5.0
CVE-2023-41829
MEDIUM
Motorola Carrier Services - Info Disclosure
CVSS 5.0
CVE-2023-41827
MEDIUM
Motorola Phones < 2023-08-01 - Improper Export of Android Application Components
CVSS 5.1
CVE-2023-41960
HIGH
Bosch Rexroth Android Agent - Exposed Content Provider Settings Modification
CVSS 7.1
CVE-2023-44129
LOW
Android 12.0-12.9 - Unauthenticated Intent Redirection via QClipIntentReceiverActivity
CVSS 3.6
CVE-2023-44121
MEDIUM
LG ThinQ Service on Android 9.0-12.0 - Intent Redirection via Broadcast Action
CVSS 5.0
CVE-2023-21486
MEDIUM
Samsung Android - Unauthenticated Data Exposure via ImagePreviewActivity Component Export
CVSS 5.3
CVE-2023-21485
MEDIUM
VideoPreviewActivity - Info Disclosure
CVSS 5.3
CVE-2023-20962
MEDIUM
Android 13 - Local Information Disclosure via Unsafe PendingIntent in MediaVolumePreferenceController
CVSS 5.5
CVE-2022-24929
MEDIUM
AppLock <SMR Mar-2022 Release 1 - Privilege Escalation
CVSS 4.1
CVE-2021-4438
MEDIUM
kyivstarteam react-native-sms-user-consent <1.1.5 - Improper Export
CVSS 5.3
CVE-2021-25527
LOW
Samsung Pay <4.1.77 - Info Disclosure
CVSS 3.8
CVE-2021-25526
MEDIUM
Samsung Blockchain Wallet <1.3.02.8 - Privilege Escalation
CVSS 4.0
CVE-2021-25400
HIGH
Samsung Internet <14.0.1.20 - Privilege Escalation
CVSS 7.8
CVE-2021-25397
MEDIUM
TelephonyUI <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 6.8
CVE-2021-25391
MEDIUM
Secure Folder <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 4.0
Details
Vulnerabilities
78