CVE-2022-20461
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 02.04.2025 16:15:20
In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege of BLE with no additional execution privileges needed. User intera...
CVE-2022-20489
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 02.04.2025 16:15:20
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVE-2022-20490
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 01.04.2025 20:15:15
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2022-20492
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:27
- Zuletzt bearbeitet 03.04.2025 20:15:16
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVE-2022-20215
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:26
- Zuletzt bearbeitet 02.04.2025 15:15:42
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitati...
CVE-2022-20235
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:15:26
- Zuletzt bearbeitet 02.04.2025 15:15:43
The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written by the GPU driver itself, but prior to DDK 1.18 however, a user-space program could write arbitrary data to the page, leading to ...
CVE-2022-20456
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:26
- Zuletzt bearbeitet 02.04.2025 15:15:43
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...
CVE-2022-20458
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:26
- Zuletzt bearbeitet 02.04.2025 15:15:44
The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the ...
CVE-2022-20213
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:15:25
- Zuletzt bearbeitet 02.04.2025 16:15:20
In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation....
CVE-2022-20214
- EPSS 0.09%
- Veröffentlicht 26.01.2023 21:15:25
- Zuletzt bearbeitet 01.04.2025 20:15:15
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11...