Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Redmi_note_6_pro_firmware
(Mi)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-06-07 | CVE-2018-20523 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request. | Redmi_4a_firmware, Redmi_5_plus_firmware, Redmi_6_firmware, Redmi_6a_firmware, Redmi_7_firmware, Redmi_7a_firmware, Redmi_go_firmware, Redmi_k20_firmware, Redmi_k20_pro_firmware, Redmi_note_4_firmware, Redmi_note_5_firmware, Redmi_note_5_pro_firmware, Redmi_note_5a_prime_firmware, Redmi_note_6_pro_firmware, Redmi_note_7_firmware, Redmi_note_7s_firmware, Redmi_s2_firmware, Redmi_y3_firmware, Stock_browser | 5.3 | ||
2019-11-14 | CVE-2019-15470 | The Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem... | Redmi_note_6_pro_firmware | N/A |