- EPSS 0.05%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:31
A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.
CVE-2022-23427
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:32
PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.
CVE-2022-23428
- EPSS 0.01%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:32
An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
CVE-2022-23429
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:32
An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.
CVE-2022-23431
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:32
An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
CVE-2022-23432
- EPSS 0.02%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:32
An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
CVE-2021-39635
- EPSS 0.08%
- Veröffentlicht 11.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:19:51
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVer...
- EPSS 0.1%
- Veröffentlicht 11.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:19:54
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify ...
CVE-2021-39662
- EPSS 0.01%
- Veröffentlicht 11.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:19:55
In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privileges neede...
CVE-2021-39663
- EPSS 0.01%
- Veröffentlicht 11.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:19:56
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is ...