OnePlus records
15 published records for vendor oneplus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-269 Improper Privilege Management2
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-476 NULL Pointer Dereference1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-5626No exploit | OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to oneplus · oxygenos | Critical9.8 | — | 2.8% | Mar 12, 2017 |
40Plan | CVE-2017-5624No exploit | An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T.oneplus · oxygenos · CWE-269 | Critical9.8 | — | 2.7% | Mar 12, 2017 |
39Monitor | CVE-2017-11105No exploit | The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate.oneplus · primary bootloader | Critical9.8 | — | 1.6% | Aug 3, 2017 |
39Monitor | CVE-2023-26309No exploit | A remote code execution vulnerability in the webview componentoneplus · store | Critical9.8 | — | 0.8% | Aug 10, 2023 |
33Monitor | CVE-2017-5554No exploit | An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2.oneplus · oxygenos · CWE-287 | High8.1 | — | 3.0% | Jan 23, 2017 |
30Monitor | CVE-2016-10370No exploit | An issue was discovered on OnePlus devices such as the 3T.oneplus · oxygenos · CWE-284 | High7.5 | — | 1.1% | May 11, 2017 |
27Monitor | CVE-2017-5947No exploit | An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier.oneplus · oxygenos | Medium6.8 | — | 0.3% | Mar 29, 2018 |
26Monitor | CVE-2017-5623No exploit | An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices.oneplus · oxygenos · CWE-269 | Medium6.6 | — | 0.4% | Mar 19, 2017 |
24Monitor | CVE-2020-7958No exploit | An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA.oneplus · oneplus 7 pro firmware | Medium6.0 | — | 0.6% | Apr 14, 2020 |
23Monitor | CVE-2017-5948No exploit | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.oneplus · oxygenos · CWE-20 | Medium5.9 | — | 0.8% | May 11, 2017 |
23Monitor | CVE-2017-8851No exploit | An issue was discovered on OnePlus One and X devices.oneplus · oxygenos · CWE-319 | Medium5.9 | — | 0.5% | May 11, 2017 |
23Monitor | CVE-2017-8850No exploit | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.oneplus · oxygenos · CWE-319 | Medium5.9 | — | 0.4% | May 11, 2017 |
23Monitor | CVE-2017-5622No exploit | With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled.oneplus · oxygenos · CWE-276 | Medium5.9 | — | 0.3% | Mar 26, 2017 |
18Monitor | CVE-2017-5625No exploit | In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertexoneplus · oxygenos · CWE-476 | Medium4.6 | — | 0.3% | Apr 25, 2017 |
18Monitor | CVE-2020-13626No exploit | OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in ordeoneplus · app locker · CWE-862 | Medium4.6 | — | 0.3% | Oct 9, 2020 |
- CVE-2017-562640Plan
OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to
CriticalCVSS 9.8No exploitEPSS 3%oneplus · oxygenosMar 12, 2017
- CVE-2017-562440Plan
An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T.
CriticalCVSS 9.8No exploitEPSS 3%oneplus · oxygenosMar 12, 2017
- CVE-2017-1110539Monitor
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate.
CriticalCVSS 9.8No exploitEPSS 2%oneplus · primary bootloaderAug 3, 2017
- CVE-2023-2630939Monitor
A remote code execution vulnerability in the webview component
CriticalCVSS 9.8No exploitEPSS 1%oneplus · storeAug 10, 2023
- CVE-2017-555433Monitor
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2.
HighCVSS 8.1No exploitEPSS 3%oneplus · oxygenosJan 23, 2017
- CVE-2016-1037030Monitor
An issue was discovered on OnePlus devices such as the 3T.
HighCVSS 7.5No exploitEPSS 1%oneplus · oxygenosMay 11, 2017
- CVE-2017-594727Monitor
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier.
MediumCVSS 6.8No exploitEPSS 0%oneplus · oxygenosMar 29, 2018
- CVE-2017-562326Monitor
An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices.
MediumCVSS 6.6No exploitEPSS 0%oneplus · oxygenosMar 19, 2017
- CVE-2020-795824Monitor
An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA.
MediumCVSS 6.0No exploitEPSS 1%oneplus · oneplus 7 pro firmwareApr 14, 2020
- CVE-2017-594823Monitor
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.
MediumCVSS 5.9No exploitEPSS 1%oneplus · oxygenosMay 11, 2017
- CVE-2017-885123Monitor
An issue was discovered on OnePlus One and X devices.
MediumCVSS 5.9No exploitEPSS 0%oneplus · oxygenosMay 11, 2017
- CVE-2017-885023Monitor
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.
MediumCVSS 5.9No exploitEPSS 0%oneplus · oxygenosMay 11, 2017
- CVE-2017-562223Monitor
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled.
MediumCVSS 5.9No exploitEPSS 0%oneplus · oxygenosMar 26, 2017
- CVE-2017-562518Monitor
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertex
MediumCVSS 4.6No exploitEPSS 0%oneplus · oxygenosApr 25, 2017
- CVE-2020-1362618Monitor
OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in orde
MediumCVSS 4.6No exploitEPSS 0%oneplus · app lockerOct 9, 2020