Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20216 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2022 | android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916 | ||
| CVE-2022-20210 | Cri | 0.64 | 9.8 | 0.04 | Jun 15, 2022 | The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which… | ||
| CVE-2022-20191 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A | ||
| CVE-2022-20173 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A | ||
| CVE-2022-20171 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A | ||
| CVE-2022-20170 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A | ||
| CVE-2022-20167 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A | ||
| CVE-2022-20164 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A | ||
| CVE-2022-20160 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A | ||
| CVE-2022-20145 | Cri | 0.64 | 9.8 | 0.07 | Jun 15, 2022 | In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is… | ||
| CVE-2022-20140 | Cri | 0.64 | 9.8 | 0.09 | Jun 15, 2022 | In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20130 | Cri | 0.64 | 9.8 | 0.09 | Jun 15, 2022 | In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20127 | Cri | 0.64 | 9.8 | 0.07 | Jun 15, 2022 | In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10… | ||
| CVE-2022-20120 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A | ||
| CVE-2021-39737 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A | ||
| CVE-2021-39723 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A | ||
| CVE-2021-39720 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A | ||
| CVE-2021-39710 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A | ||
| CVE-2021-39708 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-39675 | Cri | 0.64 | 9.8 | 0.06 | Feb 11, 2022 | In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… |
- risk 0.64cvss 9.8epss 0.01
android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916
- risk 0.64cvss 9.8epss 0.04
The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which…
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A
- risk 0.64cvss 9.8epss 0.07
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is…
- risk 0.64cvss 9.8epss 0.09
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.64cvss 9.8epss 0.09
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.07
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A
- risk 0.64cvss 9.8epss 0.01
In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.06
In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
Page 8 of 426