OPPO kayıtları
oppo üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write4
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-23 Relative Path Traversal1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
- CWE-908 Use of Uninitialized Resource1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-23247İstismar yok | A command injection vulerability found in quick game engine allows arbitrary remote code in quick app.oppo · quick app · CWE-77 | Kritik9,8 | — | %1,8 | 1 Nis 2022 |
39İzleyin | CVE-2020-11830İstismar yok | QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.oppo · qualityprotect | Kritik9,8 | — | %1,5 | 19 Kas 2020 |
39İzleyin | CVE-2020-11831İstismar yok | OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.oppo · ovoicemanager · CWE-732 | Kritik9,8 | — | %1,4 | 19 Kas 2020 |
39İzleyin | CVE-2020-11829İstismar yok | Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493oppo · coloros | Kritik9,8 | — | %1,1 | 19 Kas 2020 |
39İzleyin | CVE-2023-26310İstismar yok | Command Injection In OPPO Serviceoppo · coloros · CWE-88 | Kritik9,8 | — | %1,1 | 9 Ağu 2023 |
39İzleyin | CVE-2023-26311İstismar yok | A remote code execution vulnerability in the webview component of OPPO Store app.oppo · oppo store | Kritik9,8 | — | %0,8 | 10 Ağu 2023 |
39İzleyin | CVE-2026-22070İstismar yok | ColorOS Assistant Path Traversal Vulnerabilityoppo · coloros assistant · CWE-23 | Kritik9,8 | — | %0,2 | 30 Nis 2026 |
31İzleyin | CVE-2021-23244İstismar yok | ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelisoppo · coloros | Yüksek7,8 | — | %0,6 | 27 Ara 2021 |
31İzleyin | CVE-2018-14996İstismar yok | The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-installoppo · f5 firmware | Yüksek7,8 | — | %0,5 | 25 Nis 2019 |
31İzleyin | CVE-2021-23243İstismar yok | In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.oppo · oppo a12 | Yüksek7,8 | — | %0,1 | 27 Eyl 2021 |
30İzleyin | CVE-2020-11828İstismar yok | In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), Roppo · coloros · CWE-908 | Yüksek7,5 | — | %1,2 | 21 Nis 2020 |
30İzleyin | CVE-2021-23246İstismar yok | In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosuroppo · coloros | Yüksek7,5 | — | %1,0 | 11 Mar 2022 |
30İzleyin | CVE-2024-1608İstismar yok | OPPO Usercenter Credit sdkoppo · usercenter credit software development kit · CWE-280 | Yüksek7,5 | — | %0,5 | 20 Şub 2024 |
22İzleyin | CVE-2020-11834İstismar yok | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write oppo · reno3 pro firmware · CWE-787 | Orta5,5 | — | %0,3 | 31 Ara 2020 |
22İzleyin | CVE-2020-11835İstismar yok | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_oppo · reno3 pro firmware · CWE-787 | Orta5,5 | — | %0,3 | 31 Ara 2020 |
22İzleyin | CVE-2020-11833İstismar yok | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write doppo · reno3 pro firmware · CWE-787 | Orta5,5 | — | %0,3 | 31 Ara 2020 |
22İzleyin | CVE-2020-11832İstismar yok | In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c oppo · reno3 pro firmware · CWE-787 | Orta5,5 | — | %0,3 | 31 Ara 2020 |
22İzleyin | CVE-2020-11836İstismar yok | OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability.oppo · a12 | Orta5,5 | — | %0,1 | 5 Şub 2021 |
- CVE-2021-2324740Planlayın
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app.
KritikCVSS 9,8İstismar yokEPSS %2oppo · quick app1 Nis 2022
- CVE-2020-1183039İzleyin
QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.
KritikCVSS 9,8İstismar yokEPSS %1oppo · qualityprotect19 Kas 2020
- CVE-2020-1183139İzleyin
OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.
KritikCVSS 9,8İstismar yokEPSS %1oppo · ovoicemanager19 Kas 2020
- CVE-2020-1182939İzleyin
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493
KritikCVSS 9,8İstismar yokEPSS %1oppo · coloros19 Kas 2020
- CVE-2023-2631039İzleyin
Command Injection In OPPO Service
KritikCVSS 9,8İstismar yokEPSS %1oppo · coloros9 Ağu 2023
- CVE-2023-2631139İzleyin
A remote code execution vulnerability in the webview component of OPPO Store app.
KritikCVSS 9,8İstismar yokEPSS %1oppo · oppo store10 Ağu 2023
- CVE-2026-2207039İzleyin
ColorOS Assistant Path Traversal Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0oppo · coloros assistant30 Nis 2026
- CVE-2021-2324431İzleyin
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelis
YüksekCVSS 7,8İstismar yokEPSS %1oppo · coloros27 Ara 2021
- CVE-2018-1499631İzleyin
The Oppo F5 Android device with a build fingerprint of OPPO/CPH1723/CPH1723:7.1.1/N6F26Q/1513597833:user/release-keys contains a pre-install
YüksekCVSS 7,8İstismar yokEPSS %1oppo · f5 firmware25 Nis 2019
- CVE-2021-2324331İzleyin
In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.
YüksekCVSS 7,8İstismar yokEPSS %0oppo · oppo a1227 Eyl 2021
- CVE-2020-1182830İzleyin
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), R
YüksekCVSS 7,5İstismar yokEPSS %1oppo · coloros21 Nis 2020
- CVE-2021-2324630İzleyin
In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosur
YüksekCVSS 7,5İstismar yokEPSS %1oppo · coloros11 Mar 2022
- CVE-2024-160830İzleyin
OPPO Usercenter Credit sdk
YüksekCVSS 7,5İstismar yokEPSS %0oppo · usercenter credit software development kit20 Şub 2024
- CVE-2020-1183422İzleyin
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write
OrtaCVSS 5,5İstismar yokEPSS %0oppo · reno3 pro firmware31 Ara 2020
- CVE-2020-1183522İzleyin
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_
OrtaCVSS 5,5İstismar yokEPSS %0oppo · reno3 pro firmware31 Ara 2020
- CVE-2020-1183322İzleyin
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write d
OrtaCVSS 5,5İstismar yokEPSS %0oppo · reno3 pro firmware31 Ara 2020
- CVE-2020-1183222İzleyin
In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c
OrtaCVSS 5,5İstismar yokEPSS %0oppo · reno3 pro firmware31 Ara 2020
- CVE-2020-1183622İzleyin
OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability.
OrtaCVSS 5,5İstismar yokEPSS %0oppo · a125 Şub 2021