VYPR

Vendor CVEs

Google

All CVEs

15,856 total · sorted by risk
  • CVE-2022-20536LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20535LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution…

  • CVE-2022-20533LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20528LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20526LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20525LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-20519LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-39904LowDec 8, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.

  • CVE-2022-42769LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42767LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42758LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42757LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-20446LowNov 8, 2022
    risk 0.21cvss 3.3epss 0.00

    In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2022-3171MedOct 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be…

  • CVE-2022-39850LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

  • CVE-2022-39849LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

  • CVE-2022-36853LowSep 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

  • CVE-2022-20342LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20340LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20339LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20338LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no additional execution privileges…

  • CVE-2022-20336LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution privileges needed. User…

  • CVE-2022-20335LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20328LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20321LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2022-20320LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20318LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20316LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20315LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20311LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20310LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20309LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20307LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2022-20305LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ContentService, there is a possible disclosure of available account types due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20280LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20267LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-20262LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20257LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20252LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20251LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20249LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20241LowAug 11, 2022
    risk 0.21cvss 3.3epss 0.00

    In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20358LowAug 10, 2022
    risk 0.21cvss 3.3epss 0.00

    In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…

  • CVE-2022-33726LowAug 5, 2022
    risk 0.21cvss 3.3epss 0.00

    Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.

  • CVE-2022-33724LowAug 5, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.

  • CVE-2022-33701LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.

  • CVE-2022-33698LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.

  • CVE-2022-33697LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

  • CVE-2022-33688LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

  • CVE-2022-33687LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.

Page 277 of 318