Vendor CVEs
All CVEs
16,116 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48242 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. | ||
| CVE-2022-48241 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48234 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In FM service , there is a possible missing params check. This could lead to local denial of service in FM service . | ||
| CVE-2022-48233 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In FM service , there is a possible missing params check. This could lead to local denial of service in FM service . | ||
| CVE-2022-48232 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In FM service , there is a possible missing params check. This could lead to local denial of service in FM service . | ||
| CVE-2022-48231 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-47493 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-47492 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-47490 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-47487 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local denial of service with no additional execution privileges. | ||
| CVE-2022-47340 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-44420 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges. | ||
| CVE-2022-44419 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In modem, there is a possible missing verification of NAS Security Mode Command Replay Attacks in LTE. This could local denial of service with no additional execution privileges. | ||
| CVE-2022-38685 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed. | ||
| CVE-2023-21091 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-21087 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21082 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not… | ||
| CVE-2023-21080 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-20935 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20909 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-47468 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47467 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47466 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47465 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service. | ||
| CVE-2022-47464 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47463 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47362 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47337 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In media service, there is a missing permission check. This could lead to local denial of service in media service. | ||
| CVE-2022-47336 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2022-47335 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. | ||
| CVE-2023-21036 | Med | 0.36 | 5.5 | 0.01 | Mar 24, 2023 | In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A | ||
| CVE-2023-21033 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21029 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:… | ||
| CVE-2023-21026 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is… | ||
| CVE-2023-21019 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21016 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User… | ||
| CVE-2023-20999 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20998 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20997 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20996 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20980 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-20979 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-20974 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-20973 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-20972 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20962 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction… | ||
| CVE-2023-20952 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-20929 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-20910 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2022-42528 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… |
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
- risk 0.36cvss 5.5epss 0.00
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
- risk 0.36cvss 5.5epss 0.00
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In modem, there is a possible missing verification of NAS Security Mode Command Replay Attacks in LTE. This could local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In media service, there is a missing permission check. This could lead to local denial of service in media service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- risk 0.36cvss 5.5epss 0.01
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A
- risk 0.36cvss 5.5epss 0.00
In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…
- risk 0.36cvss 5.5epss 0.00
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is…
- risk 0.36cvss 5.5epss 0.00
In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User…
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction…
- risk 0.36cvss 5.5epss 0.00
In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
Page 215 of 323