Vendor CVEs
All CVEs
16,116 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20506 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20503 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2022 | In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2022-20611 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20495 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2022-20491 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20488 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20487 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20486 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20485 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20484 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20480 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20479 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20478 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20477 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2022-20475 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20474 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20470 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2022 | In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed… | ||
| CVE-2022-42778 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed. | ||
| CVE-2022-42777 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-42776 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed. | ||
| CVE-2022-39102 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39101 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39100 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39099 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39098 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39097 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39096 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39095 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39094 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39093 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39092 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39091 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39090 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-42533 | Hig | 0.51 | 7.8 | 0.00 | Nov 17, 2022 | In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20462 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20452 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20451 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:… | ||
| CVE-2022-20450 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20441 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User… | ||
| CVE-2021-39661 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-1050 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-32601 | Hig | 0.51 | 7.8 | 0.00 | Nov 8, 2022 | In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319132; Issue ID: ALPS07319132. | ||
| CVE-2022-39111 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39110 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39109 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39108 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed. | ||
| CVE-2022-39107 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed. | ||
| CVE-2022-39080 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-38698 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | ||
| CVE-2022-38670 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. |
- risk 0.51cvss 7.8epss 0.00
In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.51cvss 7.8epss 0.00
In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- risk 0.51cvss 7.8epss 0.00
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User…
- risk 0.51cvss 7.8epss 0.00
In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319132; Issue ID: ALPS07319132.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Page 94 of 323