CVE-2023-20928
- EPSS 0.1%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:53
In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVE-2023-20904
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:18:10
- Zuletzt bearbeitet 03.04.2025 21:15:37
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVE-2022-20493
- EPSS 0.03%
- Veröffentlicht 26.01.2023 21:15:28
- Zuletzt bearbeitet 03.04.2025 20:15:16
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exp...
CVE-2022-20494
- EPSS 1.07%
- Veröffentlicht 26.01.2023 21:15:28
- Zuletzt bearbeitet 03.04.2025 21:15:37
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...
CVE-2022-20461
- EPSS 0.05%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 02.04.2025 16:15:20
In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege of BLE with no additional execution privileges needed. User intera...
CVE-2022-20489
- EPSS 0.03%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 02.04.2025 16:15:20
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVE-2022-20490
- EPSS 0.03%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 01.04.2025 20:15:15
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2022-20492
- EPSS 0.03%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 03.04.2025 20:15:16
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVE-2022-20215
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:15:26
- Zuletzt bearbeitet 02.04.2025 15:15:42
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitati...
CVE-2022-20235
- EPSS 0.05%
- Veröffentlicht 26.01.2023 21:15:26
- Zuletzt bearbeitet 02.04.2025 15:15:43
The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written by the GPU driver itself, but prior to DDK 1.18 however, a user-space program could write arbitrary data to the page, leading to ...