Skip to content
Noroxi

OnePlus records

15 published records for vendor oneplus.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

15 records
  • OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to

    CriticalCVSS 9.8No exploitEPSS 3%

    oneplus · oxygenosMar 12, 2017

  • An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T.

    CriticalCVSS 9.8No exploitEPSS 3%

    oneplus · oxygenosMar 12, 2017

  • The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate.

    CriticalCVSS 9.8No exploitEPSS 2%

    oneplus · primary bootloaderAug 3, 2017

  • A remote code execution vulnerability in the webview component

    CriticalCVSS 9.8No exploitEPSS 1%

    oneplus · storeAug 10, 2023

  • CVE-2017-5554
    33Monitor

    An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2.

    HighCVSS 8.1No exploitEPSS 3%

    oneplus · oxygenosJan 23, 2017

  • An issue was discovered on OnePlus devices such as the 3T.

    HighCVSS 7.5No exploitEPSS 1%

    oneplus · oxygenosMay 11, 2017

  • CVE-2017-5947
    27Monitor

    An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier.

    MediumCVSS 6.8No exploitEPSS 0%

    oneplus · oxygenosMar 29, 2018

  • CVE-2017-5623
    26Monitor

    An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices.

    MediumCVSS 6.6No exploitEPSS 0%

    oneplus · oxygenosMar 19, 2017

  • CVE-2020-7958
    24Monitor

    An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA.

    MediumCVSS 6.0No exploitEPSS 1%

    oneplus · oneplus 7 pro firmwareApr 14, 2020

  • CVE-2017-5948
    23Monitor

    An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.

    MediumCVSS 5.9No exploitEPSS 1%

    oneplus · oxygenosMay 11, 2017

  • CVE-2017-8851
    23Monitor

    An issue was discovered on OnePlus One and X devices.

    MediumCVSS 5.9No exploitEPSS 0%

    oneplus · oxygenosMay 11, 2017

  • CVE-2017-8850
    23Monitor

    An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.

    MediumCVSS 5.9No exploitEPSS 0%

    oneplus · oxygenosMay 11, 2017

  • CVE-2017-5622
    23Monitor

    With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled.

    MediumCVSS 5.9No exploitEPSS 0%

    oneplus · oxygenosMar 26, 2017

  • CVE-2017-5625
    18Monitor

    In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertex

    MediumCVSS 4.6No exploitEPSS 0%

    oneplus · oxygenosApr 25, 2017

  • OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in orde

    MediumCVSS 4.6No exploitEPSS 0%

    oneplus · app lockerOct 9, 2020