CVE-2022-20441
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution...
CVE-2022-20445
- EPSS 0.24%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 20:15:31
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not neede...
CVE-2022-20446
- EPSS 0.02%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 20:15:31
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileg...
CVE-2022-20447
- EPSS 0.08%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita...
CVE-2022-20448
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:20
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVE-2022-20450
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:21
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVE-2022-20451
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:21
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed f...
CVE-2022-20452
- EPSS 0.05%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:21
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...
CVE-2022-20453
- EPSS 0.01%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:21
In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is ...
CVE-2022-20454
- EPSS 0.02%
- Veröffentlicht 08.11.2022 22:15:11
- Zuletzt bearbeitet 01.05.2025 16:15:21
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...