OnePlus kayıtları
oneplus üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-269 Improper Privilege Management2
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-476 NULL Pointer Dereference1
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-5626İstismar yok | OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to oneplus · oxygenos | Kritik9,8 | — | %2,8 | 12 Mar 2017 |
40Planlayın | CVE-2017-5624İstismar yok | An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T.oneplus · oxygenos · CWE-269 | Kritik9,8 | — | %2,7 | 12 Mar 2017 |
39İzleyin | CVE-2017-11105İstismar yok | The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate.oneplus · primary bootloader | Kritik9,8 | — | %1,6 | 3 Ağu 2017 |
39İzleyin | CVE-2023-26309İstismar yok | A remote code execution vulnerability in the webview componentoneplus · store | Kritik9,8 | — | %0,8 | 10 Ağu 2023 |
33İzleyin | CVE-2017-5554İstismar yok | An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2.oneplus · oxygenos · CWE-287 | Yüksek8,1 | — | %3,0 | 23 Oca 2017 |
30İzleyin | CVE-2016-10370İstismar yok | An issue was discovered on OnePlus devices such as the 3T.oneplus · oxygenos · CWE-284 | Yüksek7,5 | — | %1,1 | 11 May 2017 |
27İzleyin | CVE-2017-5947İstismar yok | An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier.oneplus · oxygenos | Orta6,8 | — | %0,3 | 29 Mar 2018 |
26İzleyin | CVE-2017-5623İstismar yok | An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices.oneplus · oxygenos · CWE-269 | Orta6,6 | — | %0,4 | 19 Mar 2017 |
24İzleyin | CVE-2020-7958İstismar yok | An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA.oneplus · oneplus 7 pro firmware | Orta6,0 | — | %0,6 | 14 Nis 2020 |
23İzleyin | CVE-2017-5948İstismar yok | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.oneplus · oxygenos · CWE-20 | Orta5,9 | — | %0,8 | 11 May 2017 |
23İzleyin | CVE-2017-8851İstismar yok | An issue was discovered on OnePlus One and X devices.oneplus · oxygenos · CWE-319 | Orta5,9 | — | %0,5 | 11 May 2017 |
23İzleyin | CVE-2017-8850İstismar yok | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.oneplus · oxygenos · CWE-319 | Orta5,9 | — | %0,4 | 11 May 2017 |
23İzleyin | CVE-2017-5622İstismar yok | With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled.oneplus · oxygenos · CWE-276 | Orta5,9 | — | %0,3 | 26 Mar 2017 |
18İzleyin | CVE-2017-5625İstismar yok | In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertexoneplus · oxygenos · CWE-476 | Orta4,6 | — | %0,3 | 25 Nis 2017 |
18İzleyin | CVE-2020-13626İstismar yok | OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in ordeoneplus · app locker · CWE-862 | Orta4,6 | — | %0,3 | 9 Eki 2020 |
- CVE-2017-562640Planlayın
OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to
KritikCVSS 9,8İstismar yokEPSS %3oneplus · oxygenos12 Mar 2017
- CVE-2017-562440Planlayın
An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T.
KritikCVSS 9,8İstismar yokEPSS %3oneplus · oxygenos12 Mar 2017
- CVE-2017-1110539İzleyin
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate.
KritikCVSS 9,8İstismar yokEPSS %2oneplus · primary bootloader3 Ağu 2017
- CVE-2023-2630939İzleyin
A remote code execution vulnerability in the webview component
KritikCVSS 9,8İstismar yokEPSS %1oneplus · store10 Ağu 2023
- CVE-2017-555433İzleyin
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2.
YüksekCVSS 8,1İstismar yokEPSS %3oneplus · oxygenos23 Oca 2017
- CVE-2016-1037030İzleyin
An issue was discovered on OnePlus devices such as the 3T.
YüksekCVSS 7,5İstismar yokEPSS %1oneplus · oxygenos11 May 2017
- CVE-2017-594727İzleyin
An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier.
OrtaCVSS 6,8İstismar yokEPSS %0oneplus · oxygenos29 Mar 2018
- CVE-2017-562326İzleyin
An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices.
OrtaCVSS 6,6İstismar yokEPSS %0oneplus · oxygenos19 Mar 2017
- CVE-2020-795824İzleyin
An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA.
OrtaCVSS 6,0İstismar yokEPSS %1oneplus · oneplus 7 pro firmware14 Nis 2020
- CVE-2017-594823İzleyin
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.
OrtaCVSS 5,9İstismar yokEPSS %1oneplus · oxygenos11 May 2017
- CVE-2017-885123İzleyin
An issue was discovered on OnePlus One and X devices.
OrtaCVSS 5,9İstismar yokEPSS %0oneplus · oxygenos11 May 2017
- CVE-2017-885023İzleyin
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices.
OrtaCVSS 5,9İstismar yokEPSS %0oneplus · oxygenos11 May 2017
- CVE-2017-562223İzleyin
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled.
OrtaCVSS 5,9İstismar yokEPSS %0oneplus · oxygenos26 Mar 2017
- CVE-2017-562518İzleyin
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertex
OrtaCVSS 4,6İstismar yokEPSS %0oneplus · oxygenos25 Nis 2017
- CVE-2020-1362618İzleyin
OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in orde
OrtaCVSS 4,6İstismar yokEPSS %0oneplus · app locker9 Eki 2020