CVE-2022-20519
- EPSS 0.02%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 18.04.2025 16:15:16
In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User i...
CVE-2022-20520
- EPSS 0.06%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 18.04.2025 16:15:16
In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
- EPSS 0.03%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 23.04.2025 20:15:38
In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for...
CVE-2022-20522
- EPSS 0.01%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 18.04.2025 16:15:16
In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVE-2022-20523
- EPSS 0.02%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 21.04.2025 14:15:24
In IncFs_GetFilledRangesStartingFrom of incfs.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVE-2022-20524
- EPSS 0.02%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 21.04.2025 14:15:24
In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVE-2022-20525
- EPSS 0.01%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 21.04.2025 14:15:24
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVE-2022-20526
- EPSS 0.02%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 21.04.2025 14:15:24
In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi...
CVE-2022-20527
- EPSS 0.02%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 21.04.2025 14:15:24
In HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC firmware with no additional execution privileges needed. User interaction is not need...
CVE-2022-20528
- EPSS 0.05%
- Veröffentlicht 16.12.2022 16:15:17
- Zuletzt bearbeitet 18.04.2025 16:15:16
In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...