CVE-2022-39882
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:27
Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
CVE-2022-39879
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:16
- Zuletzt bearbeitet 21.11.2024 07:18:26
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
CVE-2022-20414
- EPSS 0.02%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed f...
CVE-2022-20426
- EPSS 0.03%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interacti...
CVE-2022-20441
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution...
CVE-2022-20445
- EPSS 0.24%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 20:15:31
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not neede...
CVE-2022-20446
- EPSS 0.02%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 20:15:31
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileg...
CVE-2022-20447
- EPSS 0.08%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita...
CVE-2022-20448
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVE-2022-20450
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:21
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User in...