Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-0394 – In onCreate of BluetoothPairingDialog.java, there is a possible tapjackin

In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155648639

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0394

Reference (s):

  • https://source.android.com/security/bulletin/2020-09-01
  • URL: https://source.android.com/security/bulletin/2020-09-01
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4742 - Cross-site scripting (XSS) vulnerability in system/class_link.php in the

2021-current

CVE-2014-9837 - coders/pnm.c in ImageMagick 6.9.0-1 Beta and earlier allows remote attack

2021-current

CVE-2020-10447 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul