CVE-2022-20047
- EPSS 0.01%
- Veröffentlicht 10.03.2022 17:45:02
- Zuletzt bearbeitet 21.11.2024 06:42:01
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVE-2022-20048
- EPSS 0.01%
- Veröffentlicht 10.03.2022 17:45:02
- Zuletzt bearbeitet 21.11.2024 06:42:01
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0...
CVE-2022-23729
- EPSS 0.01%
- Veröffentlicht 04.03.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:11
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
CVE-2022-23999
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:49:37
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
CVE-2022-24000
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:49:37
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
CVE-2022-24001
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:49:38
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.
CVE-2022-24925
- EPSS 0.05%
- Veröffentlicht 11.02.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:51:24
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.
CVE-2022-22291
- EPSS 0.04%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:46:34
Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.
CVE-2022-22292
- EPSS 0.04%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:46:34
Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.
CVE-2022-23425
- EPSS 0.15%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:31
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.