Oppo
oppo
16 CVEs • 68 products
Products (68)
Click to collapseToggle
Products (68)
Click to collapse
CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. |
1Oppo 1Usercenter Credit Software Development Kit Apr 2, 2025 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction. |
A remote code execution vulnerability in the webview component of OPPO Store app.
|
There is a command injection problem in the old version of the mobile phone backup app. |
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine |
In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure. |
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obta...Show more |
1Oppo 2Find X2 Pro Firmware Reno3 Pro FirmwareNov 21, 2024 Dec 31, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_write in proc_work_mode_write causes a vulnerability. |
1Oppo 2Find X2 Pro Firmware Reno3 Pro FirmwareNov 21, 2024 Dec 31, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not check the parameter len, resulting in a vulnerability. |
1Oppo 2Find X2 Pro Firmware Reno3 Pro FirmwareNov 21, 2024 Dec 31, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write does not check the parameter len which causes a vulnerability. |
1Oppo 2Find X2 Pro Firmware Reno3 Pro FirmwareNov 21, 2024 Dec 31, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c have not checked the parameters, which causes a vulnerability. |
OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1. |
QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0. |
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722. |
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to...Show more |
The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-installed platform app with a package name of com.dropboxchmod (versionCode=1, versionN...Show more |