Filtered by vendor Google
Subscriptions
Filtered by product Android
Subscriptions
Total
7842 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-20287 | 1 Google | 1 Android | 2024-08-03 | 5.5 Medium |
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204082784 | ||||
CVE-2022-20439 | 1 Google | 1 Android | 2024-08-03 | 5.5 Medium |
In Messaging, There has unauthorized provider, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242266172 | ||||
CVE-2022-20373 | 1 Google | 1 Android | 2024-08-03 | 6.4 Medium |
In st21nfc_loc_set_polaritymode of fc/st21nfc.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208269510References: N/A | ||||
CVE-2022-20418 | 1 Google | 1 Android | 2024-08-03 | 7.5 High |
In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464 | ||||
CVE-2022-20367 | 1 Google | 1 Android | 2024-08-03 | 6.7 Medium |
In construct_transaction of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-225877459References: N/A | ||||
CVE-2022-20380 | 1 Google | 1 Android | 2024-08-03 | 7.5 High |
Product: AndroidVersions: Android kernelAndroid ID: A-212625740References: N/A | ||||
CVE-2022-20414 | 1 Google | 1 Android | 2024-08-03 | 5.5 Medium |
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-234441463 | ||||
CVE-2022-20409 | 1 Google | 1 Android | 2024-08-03 | 6.7 Medium |
In io_identity_cow of io_uring.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238177383References: Upstream kernel | ||||
CVE-2022-20376 | 1 Google | 1 Android | 2024-08-03 | 6.7 Medium |
In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216130110References: N/A | ||||
CVE-2022-20396 | 1 Google | 1 Android | 2024-08-03 | 5.5 Medium |
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-234440688 | ||||
CVE-2022-20386 | 1 Google | 1 Android | 2024-08-03 | 9.8 Critical |
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328 | ||||
CVE-2022-20407 | 1 Google | 1 Android | 2024-08-03 | 7.5 High |
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A | ||||
CVE-2022-20391 | 1 Google | 1 Android | 2024-08-03 | 9.8 Critical |
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000 | ||||
CVE-2022-20422 | 2 Debian, Google | 2 Debian Linux, Android | 2024-08-03 | 7.0 High |
In emulation_proc_handler of armv8_deprecated.c, there is a possible way to corrupt memory due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-237540956References: Upstream kernel | ||||
CVE-2022-20285 | 1 Google | 1 Android | 2024-08-03 | 5.5 Medium |
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230868108 | ||||
CVE-2022-20372 | 1 Google | 1 Android | 2024-08-03 | 6.7 Medium |
In exynos5_i2c_irq of (TBD), there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195480799References: N/A | ||||
CVE-2022-20364 | 1 Google | 1 Android | 2024-08-03 | 7.8 High |
In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-233606615References: N/A | ||||
CVE-2022-20349 | 1 Google | 1 Android | 2024-08-03 | 7.8 High |
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315522 | ||||
CVE-2022-20330 | 1 Google | 1 Android | 2024-08-03 | 3.5 Low |
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-181962588 | ||||
CVE-2022-20394 | 1 Google | 1 Android | 2024-08-03 | 5.0 Medium |
In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-204906124 |