- EPSS 0.01%
- Veröffentlicht 10.05.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:11
In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVE-2022-20119
- EPSS 0.02%
- Veröffentlicht 10.05.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:11
In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
- EPSS 1.04%
- Veröffentlicht 10.05.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:11
Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A
CVE-2022-20121
- EPSS 0.02%
- Veröffentlicht 10.05.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:11
In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2021-39738
- EPSS 0.03%
- Veröffentlicht 10.05.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:07
In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2022-20008
- EPSS 0.06%
- Veröffentlicht 10.05.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:56
In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges ...
CVE-2022-20009
- EPSS 0.34%
- Veröffentlicht 10.05.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:56
In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
CVE-2022-20010
- EPSS 0.41%
- Veröffentlicht 10.05.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:56
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is n...
CVE-2022-20011
- EPSS 0.05%
- Veröffentlicht 10.05.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:56
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is n...
CVE-2022-20112
- EPSS 0.01%
- Veröffentlicht 10.05.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:10
In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privil...