VYPR

Vendor CVEs

Google

All CVEs

16,116 total · sorted by risk
  • CVE-2022-20506HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20503HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20611HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20495HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20491HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20488HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20487HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20486HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20485HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20484HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20480HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20479HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20478HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20477HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20475HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20474HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20470HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-42778HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.

  • CVE-2022-42777HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-42776HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.

  • CVE-2022-39102HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39101HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39100HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39099HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39098HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39097HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39096HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39095HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39094HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39093HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39092HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39091HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-39090HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

  • CVE-2022-42533HigNov 17, 2022
    risk 0.51cvss 7.8epss 0.00

    In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20462HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20452HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20451HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20450HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20441HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User…

  • CVE-2021-39661HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1050HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-32601HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319132; Issue ID: ALPS07319132.

  • CVE-2022-39111HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39110HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39109HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39108HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.

  • CVE-2022-39107HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.

  • CVE-2022-39080HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-38698HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

  • CVE-2022-38670HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.

Page 94 of 323