CVE-2022-39883
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:18
- Zuletzt bearbeitet 21.11.2024 07:18:27
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
CVE-2022-39884
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:18
- Zuletzt bearbeitet 21.11.2024 07:18:27
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
CVE-2022-39885
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:18
- Zuletzt bearbeitet 21.11.2024 07:18:27
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
CVE-2022-39886
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:18
- Zuletzt bearbeitet 21.11.2024 07:18:27
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
CVE-2022-39887
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:18
- Zuletzt bearbeitet 21.11.2024 07:18:27
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
CVE-2022-39880
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:27
Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.
CVE-2022-39882
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:17
- Zuletzt bearbeitet 21.11.2024 07:18:27
Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
CVE-2022-39879
- EPSS 0.02%
- Veröffentlicht 09.11.2022 22:15:16
- Zuletzt bearbeitet 21.11.2024 07:18:26
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
CVE-2022-20414
- EPSS 0.02%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed f...
CVE-2022-20426
- EPSS 0.02%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interacti...