Skip to content
Noroxi

OPPO records

18 published records for vendor oppo.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

18 records
  • A command injection vulerability found in quick game engine allows arbitrary remote code in quick app.

    CriticalCVSS 9.8No exploitEPSS 2%

    oppo · quick appApr 1, 2022

  • QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    oppo · qualityprotectNov 19, 2020

  • OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    oppo · ovoicemanagerNov 19, 2020

  • Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493

    CriticalCVSS 9.8No exploitEPSS 1%

    oppo · colorosNov 19, 2020

  • Command Injection In OPPO Service

    CriticalCVSS 9.8No exploitEPSS 1%

    oppo · colorosAug 9, 2023

  • A remote code execution vulnerability in the webview component of OPPO Store app.

    CriticalCVSS 9.8No exploitEPSS 1%

    oppo · oppo storeAug 10, 2023

  • ColorOS Assistant Path Traversal Vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    oppo · coloros assistantApr 30, 2026

  • ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelis

    HighCVSS 7.8No exploitEPSS 1%

    oppo · colorosDec 27, 2021

  • The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-install

    HighCVSS 7.8No exploitEPSS 1%

    oppo · f5 firmwareApr 25, 2019

  • In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.

    HighCVSS 7.8No exploitEPSS 0%

    oppo · oppo a12Sep 27, 2021

  • In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), R

    HighCVSS 7.5No exploitEPSS 1%

    oppo · colorosApr 21, 2020

  • In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosur

    HighCVSS 7.5No exploitEPSS 1%

    oppo · colorosMar 11, 2022

  • CVE-2024-1608
    30Monitor

    OPPO Usercenter Credit sdk

    HighCVSS 7.5No exploitEPSS 0%

    oppo · usercenter credit software development kitFeb 20, 2024

  • In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write

    MediumCVSS 5.5No exploitEPSS 0%

    oppo · reno3 pro firmwareDec 31, 2020

  • In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_

    MediumCVSS 5.5No exploitEPSS 0%

    oppo · reno3 pro firmwareDec 31, 2020

  • In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write d

    MediumCVSS 5.5No exploitEPSS 0%

    oppo · reno3 pro firmwareDec 31, 2020

  • In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c

    MediumCVSS 5.5No exploitEPSS 0%

    oppo · reno3 pro firmwareDec 31, 2020

  • OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability.

    MediumCVSS 5.5No exploitEPSS 0%

    oppo · a12Feb 5, 2021