- EPSS 0.1%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:22
android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916
CVE-2022-20217
- EPSS 0.11%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:22
There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn contact.Product: AndroidVersions: Android SoCAndroid ID: A-232441378
CVE-2022-20218
- EPSS 0.01%
- Veröffentlicht 13.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:42:22
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2022-33703
- EPSS 0.01%
- Veröffentlicht 12.07.2022 14:15:18
- Zuletzt bearbeitet 21.11.2024 07:08:22
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
CVE-2022-33704
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:18
- Zuletzt bearbeitet 21.11.2024 07:08:22
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
CVE-2022-33685
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:17
- Zuletzt bearbeitet 21.11.2024 07:08:19
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.
CVE-2022-33686
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:17
- Zuletzt bearbeitet 21.11.2024 07:08:19
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
CVE-2022-33687
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:17
- Zuletzt bearbeitet 21.11.2024 07:08:19
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
CVE-2022-33688
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:17
- Zuletzt bearbeitet 21.11.2024 07:08:19
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
CVE-2022-33689
- EPSS 0.02%
- Veröffentlicht 12.07.2022 14:15:17
- Zuletzt bearbeitet 21.11.2024 07:08:20
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.