CVE-2022-20234
- EPSS 0.11%
- Veröffentlicht 13.07.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:24
In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a benign pkgTitl...
CVE-2022-20236
- EPSS 0.14%
- Veröffentlicht 13.07.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:24
A drm driver have oob problem, could cause the system crash or EOPProduct: AndroidVersions: Android SoCAndroid ID: A-233124709
- EPSS 0.17%
- Veröffentlicht 13.07.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:25
'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploit...
CVE-2022-20212
- EPSS 0.02%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:21
In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for expl...
- EPSS 0.13%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:22
android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916
CVE-2022-20217
- EPSS 0.12%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:22
There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn contact.Product: AndroidVersions: Android SoCAndroid ID: A-232441378
CVE-2022-20218
- EPSS 0.01%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:22
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2022-33703
- EPSS 0.01%
- Veröffentlicht 12.07.2022 14:15:18
- Zuletzt bearbeitet 21.11.2024 07:08:22
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
CVE-2022-33704
- EPSS 0.04%
- Veröffentlicht 12.07.2022 14:15:18
- Zuletzt bearbeitet 21.11.2024 07:08:22
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
CVE-2022-33685
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:17
- Zuletzt bearbeitet 21.11.2024 07:08:19
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.