Google Security Advisories · December 2022 — Google Security Advisories
745 advisories 451 CVEs 18 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2022-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 18 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-42475

Project ZeroExploitedCISA KEV listed2022-12-12

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

CVEs:CVE-2022-42475

Upstream advisory

CVE-2022-42475

GoogleExploitedCISA KEV listedCRITICAL2022-12-12

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a...

CVEs:CVE-2022-42475

Affected products

ProductStatusVendorPackageEcosystem
fortios affected fortinet
fortiproxy affected fortinet
Upstream advisory

SUSE-SU-2022:4439-1

Open SourceExploitedCISA KEV listedHIGH2022-12-13

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
golang-github-boynux-squid_exporter affected SUSE:Manager Client Tools 12 golang-github-boynux-squid_exporter
grafana affected SUSE:Manager Client Tools 12 grafana
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 12 prometheus-blackbox_exporter
spacecmd affected SUSE:Manager Client Tools 12 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 12 spacewalk-client-tools
Upstream advisory

SUSE-SU-2022:4437-1

Open SourceExploitedCISA KEV listedHIGH2022-12-13

Security update for SUSE Manager Client Tools

Affected products

ProductStatusVendorPackageEcosystem
dracut-saltboot affected openSUSE:Leap 15.3 dracut-saltboot
dracut-saltboot affected SUSE:Manager Client Tools 15 dracut-saltboot
dracut-saltboot affected openSUSE:Leap 15.4 dracut-saltboot
dracut-saltboot affected SUSE:Manager Client Tools for SLE Micro 5 dracut-saltboot
golang-github-boynux-squid_exporter affected SUSE:Manager Proxy Module 4.3 golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter affected openSUSE:Leap 15.4 golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter affected SUSE:Manager Proxy Module 4.2 golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter affected openSUSE:Leap 15.3 golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter affected SUSE:Manager Client Tools 15 golang-github-boynux-squid_exporter
golang-github-prometheus-promu affected openSUSE:Leap 15.3 golang-github-prometheus-promu
golang-github-prometheus-promu affected openSUSE:Leap 15.4 golang-github-prometheus-promu
grafana affected SUSE:Manager Client Tools 15 grafana
prometheus-blackbox_exporter affected SUSE:Manager Proxy Module 4.3 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Client Tools 15 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Client Tools for SLE Micro 5 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected SUSE:Manager Proxy Module 4.2 prometheus-blackbox_exporter
prometheus-blackbox_exporter affected openSUSE:Leap 15.4 prometheus-blackbox_exporter
spacecmd affected SUSE:Manager Client Tools 15 spacecmd
spacecmd affected openSUSE:Leap 15.3 spacecmd
spacecmd affected openSUSE:Leap 15.4 spacecmd
spacewalk-client-tools affected SUSE:Manager Client Tools 15 spacewalk-client-tools
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools for SLE Micro 5 uyuni-proxy-systemd-services
uyuni-proxy-systemd-services affected SUSE:Manager Client Tools 15 uyuni-proxy-systemd-services
wire affected openSUSE:Leap 15.4 wire
Upstream advisory

MGASA-2022-0451

Open SourceExploitedCISA KEV listedCRITICAL2022-12-06

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:10236-1

Open SourceExploitedCISA KEV listed2022-12-08

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5295-1

Open SourceExploitedCISA KEV listed2022-12-04

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-4262

GoogleExploitedCISA KEV listedHIGH2022-12-02

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4262

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4262

Open SourceExploitedCISA KEV listedHIGH2022-12-02

DEBIAN-CVE-2022-4262

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
Upstream advisory

CVE-2022-4262

Project ZeroExploitedCISA KEV listed2022-12-02

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4262

Upstream advisory

CVE-2022-42856

Project ZeroExploitedCISA KEV listed2022-12-13

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..

CVEs:CVE-2022-42856

Upstream advisory

CVE-2022-42856

GoogleExploitedCISA KEV listedCRITICAL2022-12-13

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execut...

CVEs:CVE-2022-42856

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2022-27518

GoogleExploitedCISA KEV listedCRITICAL2022-12-13

Unauthenticated remote arbitrary code execution

CVEs:CVE-2022-27518

Affected products

ProductStatusVendorPackageEcosystem
application_delivery_controller_firmware affected citrix
gateway_firmware affected citrix
Upstream advisory

RHSA-2022:8866

Open SourceActive exploitation (sightings)HIGH2022-12-07

Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (python-XStatic-Angular) security update

Affected products

ProductStatusVendorPackageEcosystem
python3-XStatic-Angular affected Red Hat:openstack:16.1::el8 python3-XStatic-Angular
python-XStatic-Angular affected Red Hat:openstack:16.1::el8 python-XStatic-Angular
XStatic-Angular-common affected Red Hat:openstack:16.1::el8 XStatic-Angular-common
Upstream advisory

RHSA-2022:8849

Open SourceActive exploitation (sightings)HIGH2022-12-07

Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.4 (python-XStatic-Angular) security update

Affected products

ProductStatusVendorPackageEcosystem
python3-XStatic-Angular affected Red Hat:openstack:16.2::el8 python3-XStatic-Angular
python-XStatic-Angular affected Red Hat:openstack:16.2::el8 python-XStatic-Angular
XStatic-Angular-common affected Red Hat:openstack:16.2::el8 XStatic-Angular-common
Upstream advisory

OESA-2022-2139

Open SourceActive exploitation (sightings)NONE2022-12-17

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:20.03-LTS-SP1 kubernetes
Upstream advisory

CVE-2022-20607

Open SourceActive exploitation (sightings)HIGH2022-12-05

In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...

CVEs:CVE-2022-20607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-238914868

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-238914868

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20603

Open SourceActive exploitation (sightings)HIGH2022-12-05

In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-219265339

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-219265339

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20606

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In SAEMM_MiningCodecTableWithMsgIE of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not nee...

CVEs:CVE-2022-20606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-233230674

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-233230674

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20516

Open SourceActive exploitation (sightings)HIGH2022-12-05

In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20516

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20605

Open SourceActive exploitation (sightings)HIGH2022-12-05

In SAECOMM_CopyBufferBytes of SAECOMM_Utility.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2022-20605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-231722405

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-231722405

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42524

Open SourceActive exploitation (sightings)HIGH2022-12-05

In sms_GetTpUdlIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-42524

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-243401445

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-243401445

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20610

Open SourceActive exploitation (sightings)HIGH2022-12-05

In cellular modem firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2022-20610

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-240462530

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-240462530

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20545

Open SourceActive exploitation (sightings)HIGH2022-12-05

In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2022-20545

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42529

Open SourceActive exploitation (sightings)CRITICAL2022-12-05

Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

CVEs:CVE-2022-42529

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-235292841

GoogleActive exploitation (sightings)2022-12-01

PUB-A-235292841

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2022-2582

Open SourceActive exploitation (sightings)CRITICAL2022-12-27

DEBIAN-CVE-2022-2582

Affected products

ProductStatusVendorPackageEcosystem
golang-github-aws-aws-sdk-go affected Debian:11 golang-github-aws-aws-sdk-go
golang-github-aws-aws-sdk-go affected Debian:12 golang-github-aws-aws-sdk-go
golang-github-aws-aws-sdk-go affected Debian:13 golang-github-aws-aws-sdk-go
golang-github-aws-aws-sdk-go affected Debian:14 golang-github-aws-aws-sdk-go
Upstream advisory

CVE-2022-20530

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2022-20530

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20601

Open SourceActive exploitation (sightings)HIGH2022-12-05

Product: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/A

CVEs:CVE-2022-20601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20602

Open SourceActive exploitation (sightings)HIGH2022-12-05

Product: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/A

CVEs:CVE-2022-20602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-204541506

GoogleActive exploitation (sightings)2022-12-01

PUB-A-204541506

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-211081867

GoogleActive exploitation (sightings)2022-12-01

PUB-A-211081867

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20604

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In SAECOMM_SetDcnIdForPlmn of SAECOMM_DbManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from a single device with no additional execution privileges needed. User inter...

CVEs:CVE-2022-20604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-230463606

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-230463606

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20474

Open SourceActive exploitation (sightings)HIGH2022-12-05

In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...

CVEs:CVE-2022-20474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20517

Open SourceActive exploitation (sightings)HIGH2022-12-05

In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20517

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20518

Open SourceActive exploitation (sightings)HIGH2022-12-05

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro...

CVEs:CVE-2022-20518

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-220738351

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-220738351

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20520

Open SourceActive exploitation (sightings)HIGH2022-12-05

In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...

CVEs:CVE-2022-20520

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20497

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreen due to an incorrect state transition. This could lead to local information disclosure with physical access re...

CVEs:CVE-2022-20497

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20581

Open SourceActive exploitation (sightings)HIGH2022-12-05

In the Pixel camera driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2022-20581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-245916120

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-245916120

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20591

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2022-20591

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-238939706

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-238939706

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20540

Open SourceActive exploitation (sightings)HIGH2022-12-05

In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20540

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20598

Open SourceActive exploitation (sightings)HIGH2022-12-05

In sec_media_protect of media.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege of secure mode MFC Core with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20600

Open SourceActive exploitation (sightings)HIGH2022-12-05

In TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...

CVEs:CVE-2022-20600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239847859

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-239847859

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242357514

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-242357514

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20509

Open SourceActive exploitation (sightings)HIGH2022-12-05

In mapGrantorDescr of MessageQueueBase.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20509

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20514

Open SourceActive exploitation (sightings)HIGH2022-12-05

In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System ex...

CVEs:CVE-2022-20514

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20554

Open SourceActive exploitation (sightings)HIGH2022-12-05

In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2022-20554

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20563

Open SourceActive exploitation (sightings)HIGH2022-12-05

In TBD of ufdt_convert, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2022-20563

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20564

Open SourceActive exploitation (sightings)HIGH2022-12-05

In _ufdt_output_strtab_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-20564

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20569

Open SourceActive exploitation (sightings)HIGH2022-12-05

In thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interactio...

CVEs:CVE-2022-20569

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20571

Open SourceActive exploitation (sightings)HIGH2022-12-05

In extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-20571

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20577

Open SourceActive exploitation (sightings)HIGH2022-12-05

In OemSimAuthRequest::encode of wlandata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20577

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20578

Open SourceActive exploitation (sightings)HIGH2022-12-05

In RadioImpl::setGsmBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2022-20578

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20579

Open SourceActive exploitation (sightings)HIGH2022-12-05

In RadioImpl::setCdmaBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2022-20579

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20580

Open SourceActive exploitation (sightings)HIGH2022-12-05

In ufdt_do_one_fixup of ufdt_overlay.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-20580

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20596

Open SourceActive exploitation (sightings)HIGH2022-12-05

In sendChunk of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2022-20596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-229258234

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-229258234

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-234030265

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-234030265

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-239700400

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-239700400

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241762281

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-241762281

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242067561

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-242067561

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243509749

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-243509749

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243510139

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-243510139

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243629453

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-243629453

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243798789

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-243798789

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42519

Open SourceActive exploitation (sightings)HIGH2022-12-05

In CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-42519

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42520

Open SourceActive exploitation (sightings)HIGH2022-12-05

In ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...

CVEs:CVE-2022-42520

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42525

Open SourceActive exploitation (sightings)HIGH2022-12-05

In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-42525

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-242540694

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-242540694

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242994270

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-242994270

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243509750

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-243509750

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20524

Open SourceActive exploitation (sightings)HIGH2022-12-05

In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2022-20524

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42504

Open SourceActive exploitation (sightings)HIGH2022-12-05

In CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed ...

CVEs:CVE-2022-42504

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241232209

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-241232209

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42522

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In DoSetCarrierConfig of miscservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2022-42522

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-243130038

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-243130038

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20480

Open SourceActive exploitation (sightings)HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20484

Open SourceActive exploitation (sightings)HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20515

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed...

CVEs:CVE-2022-20515

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20590

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20590

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20592

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2022-20592

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-238932493

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-238932493

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-238976908

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-238976908

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20491

Open SourceActive exploitation (sightings)HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20491

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42542

Open SourceActive exploitation (sightings)HIGH2022-12-05

In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-42542

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20521

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for e...

CVEs:CVE-2022-20521

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20529

Open SourceActive exploitation (sightings)LOW2022-12-05

In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User int...

CVEs:CVE-2022-20529

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20543

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...

CVEs:CVE-2022-20543

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42509

Open SourceActive exploitation (sightings)HIGH2022-12-05

In CallDialReqData::encode of callreqdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-42509

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42513

Open SourceActive exploitation (sightings)HIGH2022-12-05

In ProtocolEmbmsBuilder::BuildSetSession of protocolembmsbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n...

CVEs:CVE-2022-42513

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42518

Open SourceActive exploitation (sightings)HIGH2022-12-05

In BroadcastSmsConfigsRequestData::encode of smsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2022-42518

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42532

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2022-42532

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241544307

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-241544307

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241763204

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-241763204

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242332610

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-242332610

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242536278

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-242536278

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42512

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In VsimOperationDataExt::encode of vsimdata.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-42512

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42514

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In ProtocolImsBuilder::BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not need...

CVEs:CVE-2022-42514

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241763050

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-241763050

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241763298

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-241763298

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20503

Open SourceActive exploitation (sightings)HIGH2022-12-05

In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

CVEs:CVE-2022-20503

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20506

Open SourceActive exploitation (sightings)HIGH2022-12-05

In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2022-20506

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20523

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In IncFs_GetFilledRangesStartingFrom of incfs.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2022-20523

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20511

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2022-20511

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20522

Open SourceActive exploitation (sightings)HIGH2022-12-05

In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2022-20522

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20482

Open SourceActive exploitation (sightings)HIGH2022-12-05

In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges neede...

CVEs:CVE-2022-20482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20519

Open SourceActive exploitation (sightings)LOW2022-12-05

In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User int...

CVEs:CVE-2022-20519

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20477

Open SourceActive exploitation (sightings)HIGH2022-12-05

In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2022-20477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32620

Open SourceActive exploitation (sightings)HIGH2022-12-05

In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07541753; Issue ID: ALPS07541753.

CVEs:CVE-2022-32620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-250441023

GoogleActive exploitation (sightings)HIGH2022-12-01

ASB-A-250441023

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-32596

Open SourceActive exploitation (sightings)HIGH2022-12-05

In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446213; Is...

CVEs:CVE-2022-32596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32597

Open SourceActive exploitation (sightings)HIGH2022-12-05

In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Is...

CVEs:CVE-2022-32597

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32598

Open SourceActive exploitation (sightings)HIGH2022-12-05

In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Is...

CVEs:CVE-2022-32598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-250470696

GoogleActive exploitation (sightings)HIGH2022-12-01

ASB-A-250470696

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-250470697

GoogleActive exploitation (sightings)HIGH2022-12-01

ASB-A-250470697

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-250470698

GoogleActive exploitation (sightings)HIGH2022-12-01

ASB-A-250470698

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42501

Open SourceActive exploitation (sightings)HIGH2022-12-05

In HexString2Value of util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2022-42501

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241231403

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-241231403

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20505

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitationProduct: An...

CVEs:CVE-2022-20505

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32594

Open SourceActive exploitation (sightings)HIGH2022-12-05

In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446207; Is...

CVEs:CVE-2022-32594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-250331397

GoogleActive exploitation (sightings)HIGH2022-12-01

ASB-A-250331397

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20496

Open SourceActive exploitation (sightings)HIGH2022-12-05

In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2022-20496

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20553

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed f...

CVEs:CVE-2022-20553

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20526

Open SourceActive exploitation (sightings)HIGH2022-12-05

In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2022-20526

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20548

Open SourceActive exploitation (sightings)HIGH2022-12-05

In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2022-20548

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20550

Open SourceActive exploitation (sightings)HIGH2022-12-05

In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20550

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20561

Open SourceActive exploitation (sightings)HIGH2022-12-05

In TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...

CVEs:CVE-2022-20561

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20584

Open SourceActive exploitation (sightings)HIGH2022-12-05

In page_number of shared_mem.c, there is a possible code execution in secure world due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20584

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20585

Open SourceActive exploitation (sightings)HIGH2022-12-05

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20585

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20586

Open SourceActive exploitation (sightings)HIGH2022-12-05

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-20586

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20587

Open SourceActive exploitation (sightings)HIGH2022-12-05

In ppmp_validate_wsm of drm_fw.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2022-20587

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-222162870

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-222162870

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-238366009

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-238366009

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-238716781

GoogleActive exploitation (sightings)NONE2022-12-01

PUB-A-238716781

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-238718854

GoogleActive exploitation (sightings)NONE2022-12-01

PUB-A-238718854

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-238720411

GoogleActive exploitation (sightings)NONE2022-12-01

PUB-A-238720411

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-240919398

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-240919398

Affected products

ProductStatusVendorPackageEcosystem
vendor/google/whitechapel/audio affected platform platform/vendor/google/whitechapel/audio
Upstream advisory

CVE-2022-20539

Open SourceActive exploitation (sightings)HIGH2022-12-05

In parameterToHal of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the audio server with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20539

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20549

Open SourceActive exploitation (sightings)HIGH2022-12-05

In authToken2AidlVec of KeyMintUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-20549

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20583

Open SourceActive exploitation (sightings)HIGH2022-12-05

In ppmp_unprotect_mfcfw_buf of drm_fw.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in S-EL1 with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20583

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20588

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In sysmmu_map of sysmmu.c, there is a possible EoP due to a precondition check failure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2022-20588

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-234859169

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-234859169

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-238785915

GoogleActive exploitation (sightings)NONE2022-12-01

PUB-A-238785915

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-235114749

GoogleActive exploitation (sightings)2022-12-01

PUB-A-235114749

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

CVE-2022-20589

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In valid_va_secbuf_check of drm_access_control.c, there is a possible ID due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:...

CVEs:CVE-2022-20589

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-238841928

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-238841928

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20546

Open SourceActive exploitation (sightings)HIGH2022-12-05

In getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2022-20546

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20199

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20199

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20485

Open SourceActive exploitation (sightings)HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20486

Open SourceActive exploitation (sightings)HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20488

Open SourceActive exploitation (sightings)HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20488

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20527

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC firmware with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2022-20527

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20538

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi...

CVEs:CVE-2022-20538

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20552

Open SourceActive exploitation (sightings)HIGH2022-12-05

In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20552

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20608

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20608

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20609

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In Pixel cellular firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...

CVEs:CVE-2022-20609

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239239246

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-239239246

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239240808

GoogleActive exploitation (sightings)MEDIUM2022-12-01

PUB-A-239240808

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20528

Open SourceActive exploitation (sightings)LOW2022-12-05

In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2022-20528

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20535

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with...

CVEs:CVE-2022-20535

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20559

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no ad...

CVEs:CVE-2022-20559

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20525

Open SourceActive exploitation (sightings)HIGH2022-12-05

In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2022-20525

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20547

Open SourceActive exploitation (sightings)HIGH2022-12-05

In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2022-20547

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20240

Open SourceActive exploitation (sightings)LOW2022-12-05

In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is ...

CVEs:CVE-2022-20240

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20533

Open SourceActive exploitation (sightings)LOW2022-12-05

In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20533

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20536

Open SourceActive exploitation (sightings)MEDIUM2022-12-05

In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2022-20536

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20537

Open SourceActive exploitation (sightings)LOW2022-12-05

In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive settings due to a missing permission check. This could lead to local escalation of privilege from the Guest user with no additional exec...

CVEs:CVE-2022-20537

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20582

Open SourceActive exploitation (sightings)HIGH2022-12-05

In ppmp_unprotect_mfcfw_buf of drm_fw.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2022-20582

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-233645166

GoogleActive exploitation (sightings)HIGH2022-12-01

PUB-A-233645166

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42771

Open SourceActive exploitation (sightings)HIGH2022-12-05

In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-253978040

GoogleActive exploitation (sightings)CRITICAL2022-12-01

ASB-A-253978040

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2021-39660

Open SourceActive exploitation (sightings)HIGH2022-12-05

In TBD of TBD, there is a possible way to archive arbitrary code execution in kernel due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2021-39660

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-254742984

GoogleActive exploitation (sightings)HIGH2022-12-01

ASB-A-254742984

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

openSUSE-SU-2022:10229-1

Open SourcePoC exploitCRITICAL2022-12-04

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DSA-5293-1

Open SourcePoC exploit2022-12-03

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

AZL-38788

Open SourcePoC exploitHIGH2022-12-23

CVE-2022-43551 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

CVE-2022-20473

Open SourcePoC exploitCRITICAL2022-12-05

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20472

Open SourcePoC exploitCRITICAL2022-12-05

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2022-0473

Open SourcePoC exploit2022-12-17

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:8 golang
Upstream advisory

GHSA-xrjj-mj9h-534m

Open SourcePoC exploitMEDIUM2022-12-08

golang.org/x/net/http2 vulnerable to possible excessive memory growth

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

GHSA-xrjj-mj9h-534m

Open SourcePoC exploitMEDIUM2022-12-08

golang.org/x/net/http2 vulnerable to possible excessive memory growth

Affected products

ProductStatusVendorPackageEcosystem
go-1.19 affected chainguard go-1.19
go-1.19 affected wolfi go-1.19
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
x/net/http2 affected golang.org
Upstream advisory

AZL-11582

Open SourcePoC exploitMEDIUM2022-12-08

CVE-2022-41717 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-34750

Open SourcePoC exploitMEDIUM2022-12-08

CVE-2022-41717 affecting package golang for versions less than 1.17.13-2,1.18.8-2,1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

AZL-37311

Open SourcePoC exploitMEDIUM2022-12-08

CVE-2022-41717 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-37374

Open SourcePoC exploitMEDIUM2022-12-08

CVE-2022-41717 affecting package golang for versions less than 1.21.6-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:2 golang
Upstream advisory

AZL-79004

Open SourcePoC exploitMEDIUM2022-12-08

CVE-2022-41717 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41717

Open SourcePoC exploitMEDIUM2022-12-08

DEBIAN-CVE-2022-41717

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
golang-golang-x-net affected Debian:11 golang-golang-x-net
golang-golang-x-net affected Debian:12 golang-golang-x-net
golang-golang-x-net affected Debian:13 golang-golang-x-net
golang-golang-x-net affected Debian:14 golang-golang-x-net
Upstream advisory

GO-2022-1144

Open SourcePoC exploit2022-12-08

Excessive memory growth in net/http and golang.org/x/net/http2

Affected products

ProductStatusVendorPackageEcosystem
kubeflow affected chainguard kubeflow
kubeflow affected wolfi kubeflow
kubeflow-fips affected chainguard kubeflow-fips
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
stdlib affected Go stdlib
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2022-41717

Open SourcePoC exploitMEDIUM2022-12-08

golang.org/x/net/http2 vulnerable to possible excessive memory growth

CVEs:CVE-2022-41717

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
x/net/http2 affected golang.org golang.org/x/net/http2
Upstream advisory

CVE-2022-41717

GooglePoC exploitMEDIUM2022-12-08

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending ver...

CVEs:CVE-2022-41717

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
go affected golang
http2 affected golang
Upstream advisory

AZL-38548

Open SourcePoC exploitCRITICAL2022-12-05

CVE-2022-32221 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

CVE-2022-20411

Open SourcePoC exploitHIGH2022-12-05

In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-20411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

AZL-38755

Open SourcePoC exploitHIGH2022-12-05

CVE-2022-35260 affecting package tensorflow for versions less than 2.16.1-1

Affected products

ProductStatusVendorPackageEcosystem
tensorflow affected Azure Linux:3 tensorflow
Upstream advisory

GHSA-6q6q-88xp-6f2r

GooglePoC exploitHIGH2022-12-28

yaml package for Go can consume excessive amounts of CPU or memory

Affected products

ProductStatusVendorPackageEcosystem
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

GHSA-6q6q-88xp-6f2r

Open SourcePoC exploitHIGH2022-12-28

yaml package for Go can consume excessive amounts of CPU or memory

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
k3d affected chainguard k3d
k3d affected wolfi k3d
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

DEBIAN-CVE-2022-3064

Open SourcePoC exploitHIGH2022-12-27

DEBIAN-CVE-2022-3064

Affected products

ProductStatusVendorPackageEcosystem
golang-yaml.v2 affected Debian:11 golang-yaml.v2
golang-yaml.v2 affected Debian:12 golang-yaml.v2
golang-yaml.v2 affected Debian:13 golang-yaml.v2
golang-yaml.v2 affected Debian:14 golang-yaml.v2
Upstream advisory

GHSA-ppp9-7jff-5vj2

Open SourcePoC exploitHIGH2022-12-26

golang.org/x/text/language Out-of-bounds Read vulnerability

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
dynamic-localpv-provisioner affected wolfi dynamic-localpv-provisioner
dynamic-localpv-provisioner affected chainguard dynamic-localpv-provisioner
dynamic-localpv-provisioner-fips affected chainguard dynamic-localpv-provisioner-fips
gitleaks affected wolfi gitleaks
gitleaks affected chainguard gitleaks
hey affected chainguard hey
hey affected wolfi hey
k3d affected chainguard k3d
k3d affected wolfi k3d
prometheus-postgres-exporter-0.10 affected chainguard prometheus-postgres-exporter-0.10
terraform-provider-sendgrid affected wolfi terraform-provider-sendgrid
terraform-provider-sendgrid affected chainguard terraform-provider-sendgrid
terraform-provider-sendgrid-fips affected chainguard terraform-provider-sendgrid-fips
vt-cli affected wolfi vt-cli
vt-cli affected chainguard vt-cli
x/text affected golang.org golang.org/x/text
x/text affected golang.org
Upstream advisory

GHSA-ppp9-7jff-5vj2

Open SourcePoC exploitHIGH2022-12-26

golang.org/x/text/language Out-of-bounds Read vulnerability

Affected products

ProductStatusVendorPackageEcosystem
x/text affected golang.org golang.org/x/text
Upstream advisory

DEBIAN-CVE-2021-38561

Open SourcePoC exploitHIGH2022-12-26

DEBIAN-CVE-2021-38561

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-text affected Debian:11 golang-golang-x-text
golang-golang-x-text affected Debian:12 golang-golang-x-text
golang-golang-x-text affected Debian:13 golang-golang-x-text
golang-golang-x-text affected Debian:14 golang-golang-x-text
Upstream advisory

AZL-79038

Open SourcePoC exploitHIGH2022-12-07

CVE-2022-41720 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

DEBIAN-CVE-2022-41720

Open SourcePoC exploitHIGH2022-12-07

DEBIAN-CVE-2022-41720

Affected products

ProductStatusVendorPackageEcosystem
golang-1.15 affected Debian:11 golang-1.15
golang-1.19 affected Debian:12 golang-1.19
Upstream advisory

CVE-2022-41720

GooglePoC exploitHIGH2022-12-07

On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For ex...

CVEs:CVE-2022-41720

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GO-2022-1143

Open SourcePoC exploitHIGH2022-12-07

Restricted file access on Windows in os and net/http

Affected products

ProductStatusVendorPackageEcosystem
kubeflow-katib affected wolfi kubeflow-katib
kubeflow-katib affected chainguard kubeflow-katib
stdlib affected Go stdlib
Upstream advisory

CVE-2022-20498

Open SourcePoC exploitMEDIUM2022-12-05

In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-20498

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-g5ww-5jh7-63cx

Open SourcePoC exploitCRITICAL2022-12-12

Protobuf Java vulnerable to Uncontrolled Resource Consumption

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
Upstream advisory

GHSA-g5ww-5jh7-63cx

Open SourcePoC exploitCRITICAL2022-12-12

Protobuf Java vulnerable to Uncontrolled Resource Consumption

Affected products

ProductStatusVendorPackageEcosystem
celeborn-0.5 affected chainguard celeborn-0.5
celeborn-0.5 affected wolfi celeborn-0.5
celeborn-0.6 affected wolfi celeborn-0.6
celeborn-0.6 affected chainguard celeborn-0.6
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
dotty affected wolfi dotty
dotty affected chainguard dotty
druid affected wolfi druid
druid affected chainguard druid
emsdk affected chainguard emsdk
hadoop-client-modules affected chainguard hadoop-client-modules
spark-3.5.0-compat affected chainguard spark-3.5.0-compat
trino affected chainguard trino
trino affected wolfi trino
Upstream advisory

DEBIAN-CVE-2022-3509

Open SourcePoC exploitHIGH2022-12-12

DEBIAN-CVE-2022-3509

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Debian:11 protobuf
protobuf affected Debian:12 protobuf
protobuf affected Debian:13 protobuf
protobuf affected Debian:14 protobuf
Upstream advisory

PUB-A-233438137

GooglePoC exploit2022-12-01

PUB-A-233438137

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

OESA-2022-2132

Open SourcePoC exploit2022-12-09

kubernetes security update

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected openEuler:20.03-LTS-SP1 kubernetes
kubernetes affected openEuler:20.03-LTS-SP3 kubernetes
kubernetes affected openEuler:22.03-LTS kubernetes
Upstream advisory

GHSA-4gg5-vx3j-xwc7

Open SourcePoC exploitCRITICAL2022-12-12

Protobuf Java vulnerable to Uncontrolled Resource Consumption

Affected products

ProductStatusVendorPackageEcosystem
celeborn-0.5 affected chainguard celeborn-0.5
celeborn-0.5 affected wolfi celeborn-0.5
celeborn-0.6 affected wolfi celeborn-0.6
celeborn-0.6 affected chainguard celeborn-0.6
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
dotty affected wolfi dotty
dotty affected chainguard dotty
druid affected wolfi druid
druid affected chainguard druid
emsdk affected chainguard emsdk
hadoop-client-modules affected chainguard hadoop-client-modules
spark-3.5.0-compat affected chainguard spark-3.5.0-compat
trino affected chainguard trino
trino affected wolfi trino
Upstream advisory

GHSA-4gg5-vx3j-xwc7

Open SourcePoC exploitCRITICAL2022-12-12

Protobuf Java vulnerable to Uncontrolled Resource Consumption

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-java affected Maven com.google.protobuf:protobuf-java
com.google.protobuf:protobuf-javalite affected Maven com.google.protobuf:protobuf-javalite
Upstream advisory

DEBIAN-CVE-2022-3510

Open SourcePoC exploitHIGH2022-12-12

DEBIAN-CVE-2022-3510

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Debian:11 protobuf
protobuf affected Debian:12 protobuf
protobuf affected Debian:13 protobuf
protobuf affected Debian:14 protobuf
Upstream advisory

DEBIAN-CVE-2017-20146

Open SourcePoC exploitCRITICAL2022-12-27

DEBIAN-CVE-2017-20146

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gorilla-handlers affected Debian:12 golang-github-gorilla-handlers
golang-github-gorilla-handlers affected Debian:11 golang-github-gorilla-handlers
golang-github-gorilla-handlers affected Debian:13 golang-github-gorilla-handlers
golang-github-gorilla-handlers affected Debian:14 golang-github-gorilla-handlers
Upstream advisory

CVE-2022-20483

Open SourcePoC exploitHIGH2022-12-05

In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User i...

CVEs:CVE-2022-20483

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-234020136

GooglePoC exploit2022-12-01

PUB-A-234020136

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

ASB-A-215557547

GooglePoC exploitMEDIUM2022-12-01

ASB-A-215557547

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-234475629

GooglePoC exploitNONE2022-12-01

PUB-A-234475629

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

GHSA-r88r-gmrh-7j83

GooglePoC exploitCRITICAL2022-12-28

YAML Go package vulnerable to denial of service

Affected products

ProductStatusVendorPackageEcosystem
go-yaml/yaml affected github.com github.com/go-yaml/yaml
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

GHSA-r88r-gmrh-7j83

Open SourcePoC exploitCRITICAL2022-12-28

YAML Go package vulnerable to denial of service

Affected products

ProductStatusVendorPackageEcosystem
dex-k8s-authenticator affected chainguard dex-k8s-authenticator
go-yaml/yaml affected github.com github.com/go-yaml/yaml
k3d affected chainguard k3d
k3d affected wolfi k3d
yaml.v2 affected gopkg.in gopkg.in/yaml.v2
Upstream advisory

DEBIAN-CVE-2021-4235

Open SourcePoC exploitCRITICAL2022-12-27

DEBIAN-CVE-2021-4235

Affected products

ProductStatusVendorPackageEcosystem
golang-yaml.v2 affected Debian:11 golang-yaml.v2
golang-yaml.v2 affected Debian:12 golang-yaml.v2
golang-yaml.v2 affected Debian:13 golang-yaml.v2
golang-yaml.v2 affected Debian:14 golang-yaml.v2
Upstream advisory

PUB-A-228694391

GooglePoC exploit2022-12-01

PUB-A-228694391

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-235183128

GooglePoC exploit2022-12-01

PUB-A-235183128

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-235540888

GooglePoC exploit2022-12-01

PUB-A-235540888

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-160818461

GooglePoC exploitHIGH2022-12-01

PUB-A-160818461

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20469

Open SourcePoC exploitHIGH2022-12-05

In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2022-20469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20470

Open SourcePoC exploitHIGH2022-12-05

In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User...

CVEs:CVE-2022-20470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-165329981

GooglePoC exploitHIGH2022-12-01

PUB-A-165329981

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20476

Open SourcePoC exploitHIGH2022-12-05

In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction ...

CVEs:CVE-2022-20476

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20468

Open SourcePoC exploitMEDIUM2022-12-05

In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2022-20468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20500

Open SourcePoC exploitMEDIUM2022-12-05

In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2022-20500

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20466

Open SourcePoC exploitMEDIUM2022-12-05

In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional exec...

CVEs:CVE-2022-20466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-44708

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVEs:CVE-2022-44708

Affected products

ProductStatusVendorPackageEcosystem
edge affected microsoft
edge_chromium affected microsoft
Upstream advisory

CVE-2022-41115

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

CVEs:CVE-2022-41115

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

DEBIAN-CVE-2020-36568

Open SourceCoalition ESS < 30%CRITICAL2022-12-27

DEBIAN-CVE-2020-36568

Affected products

ProductStatusVendorPackageEcosystem
golang-github-revel-revel affected Debian:11 golang-github-revel-revel
golang-github-revel-revel affected Debian:12 golang-github-revel-revel
golang-github-revel-revel affected Debian:13 golang-github-revel-revel
golang-github-revel-revel affected Debian:14 golang-github-revel-revel
Upstream advisory

DEBIAN-CVE-2020-36567

Open SourceCoalition ESS < 30%HIGH2022-12-27

DEBIAN-CVE-2020-36567

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gin-gonic-gin affected Debian:11 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:12 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:13 golang-github-gin-gonic-gin
golang-github-gin-gonic-gin affected Debian:14 golang-github-gin-gonic-gin
Upstream advisory

CVE-2022-44688

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVEs:CVE-2022-44688

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

CVE-2020-36628

Open SourceCoalition ESS < 30%CRITICAL2022-12-25

A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to...

CVEs:CVE-2020-36628

Affected products

ProductStatusVendorPackageEcosystem
android_processing_development_environment affected android_processing_development_environment_project
Upstream advisory

DEBIAN-CVE-2022-4122

Open SourceCoalition ESS < 30%HIGH2022-12-08

DEBIAN-CVE-2022-4122

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

CVE-2022-42527

Open SourceCoalition ESS < 30%HIGH2022-12-05

In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...

CVEs:CVE-2022-42527

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-244448906

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-244448906

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

GHSA-hrm3-3xm6-x33h

Open SourceCoalition ESS < 30%CRITICAL2022-12-28

golang-nanoauth authentication bypass vulnerability

Affected products

ProductStatusVendorPackageEcosystem
nanobox-io/golang-nanoauth affected github.com github.com/nanobox-io/golang-nanoauth
Upstream advisory

GHSA-hrm3-3xm6-x33h

Open SourceCoalition ESS < 30%CRITICAL2022-12-28

golang-nanoauth authentication bypass vulnerability

Affected products

ProductStatusVendorPackageEcosystem
nanobox-io/golang-nanoauth affected github.com github.com/nanobox-io/golang-nanoauth
Upstream advisory

CVE-2020-36569

Open SourceCoalition ESS < 30%CRITICAL2022-12-27

golang-nanoauth authentication bypass vulnerability

CVEs:CVE-2020-36569

Affected products

ProductStatusVendorPackageEcosystem
nanobox-io/golang-nanoauth affected github.com github.com/nanobox-io/golang-nanoauth
Upstream advisory

CVE-2020-36569

Open SourceCoalition ESS < 30%CRITICAL2021-04-14

Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.

CVEs:CVE-2020-36569

Affected products

ProductStatusVendorPackageEcosystem
golang-nanoauth affected digitalocean
Upstream advisory

GHSA-f5h9-qx38-2hgp

Open SourceCoalition ESS < 30%CRITICAL2022-12-27

AWS SDK is vulnerable to server-side request forgery (SSRF)

Affected products

ProductStatusVendorPackageEcosystem
com.amazonaws:aws-android-sdk-mobile-client affected Maven com.amazonaws:aws-android-sdk-mobile-client
Upstream advisory

GHSA-f5h9-qx38-2hgp

Open SourceCoalition ESS < 30%CRITICAL2022-12-27

AWS SDK is vulnerable to server-side request forgery (SSRF)

Affected products

ProductStatusVendorPackageEcosystem
com.amazonaws:aws-android-sdk-mobile-client affected Maven com.amazonaws:aws-android-sdk-mobile-client
Upstream advisory

CVE-2022-4725

GoogleCoalition ESS < 30%CRITICAL2022-12-24

A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-core/src/main/java/com/amazonaws/util/XpathUtils.java of the component XML Parser. The manipulation leads...

CVEs:CVE-2022-4725

Affected products

ProductStatusVendorPackageEcosystem
aws_software_development_kit affected amazon
Upstream advisory

CVE-2022-4725

Open SourceCoalition ESS < 30%CRITICAL2022-12-24

AWS SDK is vulnerable to server-side request forgery (SSRF)

CVEs:CVE-2022-4725

Affected products

ProductStatusVendorPackageEcosystem
com.amazonaws:aws-android-sdk-mobile-client affected Maven com.amazonaws:aws-android-sdk-mobile-client
Upstream advisory

MGASA-2022-0480

Open SourceCoalition ESS < 30%CRITICAL2022-12-24

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:8 chromium-browser-stable
Upstream advisory

openSUSE-SU-2022:10245-1

Open SourceCoalition ESS < 30%CRITICAL2022-12-16

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP3 chromium
chromium affected openSUSE:Leap 15.3 chromium
chromium affected SUSE:Package Hub 15 SP3
Upstream advisory

DSA-5302-1

Open SourceCoalition ESS < 30%2022-12-16

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
Upstream advisory

openSUSE-SU-2022:10244-1

Open SourceCoalition ESS < 30%CRITICAL2022-12-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP4 chromium
chromium affected openSUSE:Leap 15.4 chromium
Upstream advisory

DEBIAN-CVE-2022-4437

Open SourceCoalition ESS < 30%CRITICAL2022-12-14

DEBIAN-CVE-2022-4437

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2022-4438

Open SourceCoalition ESS < 30%CRITICAL2022-12-14

DEBIAN-CVE-2022-4438

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4437

GoogleCoalition ESS < 30%CRITICAL2022-12-13

Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4437

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2022-4438

GoogleCoalition ESS < 30%CRITICAL2022-12-13

Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: ...

CVEs:CVE-2022-4438

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4436

Open SourceCoalition ESS < 30%CRITICAL2022-12-14

DEBIAN-CVE-2022-4436

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4436

GoogleCoalition ESS < 30%CRITICAL2022-12-13

Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2022-4436

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4440

Open SourceCoalition ESS < 30%CRITICAL2022-12-14

DEBIAN-CVE-2022-4440

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2022-4440

GoogleCoalition ESS < 30%CRITICAL2022-12-13

Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2022-4440

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2022-4439

Open SourceCoalition ESS < 30%CRITICAL2022-12-14

DEBIAN-CVE-2022-4439

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2022-4439

GoogleCoalition ESS < 30%CRITICAL2022-12-13

Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security se...

CVEs:CVE-2022-4439

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-36627

Open SourceCoalition ESS < 30%MEDIUM2022-12-25

DEBIAN-CVE-2020-36627

Affected products

ProductStatusVendorPackageEcosystem
golang-github-go-macaron-i18n affected Debian:11 golang-github-go-macaron-i18n
Upstream advisory

GHSA-4fv8-w65m-3932

Open SourceCoalition ESS < 30%MEDIUM2022-12-30

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/aws-efs-csi-driver affected github.com github.com/kubernetes-sigs/aws-efs-csi-driver
Upstream advisory

GHSA-4fv8-w65m-3932

Open SourceCoalition ESS < 30%MEDIUM2022-12-30

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/aws-efs-csi-driver affected github.com github.com/kubernetes-sigs/aws-efs-csi-driver
Upstream advisory

CVE-2022-46174

GoogleCoalition ESS < 30%MEDIUM2022-12-28

efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a...

CVEs:CVE-2022-46174

Affected products

ProductStatusVendorPackageEcosystem
efs-utils affected amazon
elastic_file_system_container_storage_interface_driver affected amazon
Upstream advisory

CVE-2022-46174

Open SourceCoalition ESS < 30%MEDIUM2022-12-28

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

CVEs:CVE-2022-46174

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/aws-efs-csi-driver affected github.com github.com/kubernetes-sigs/aws-efs-csi-driver
Upstream advisory

CVE-2022-46174

Open SourceCoalition ESS < 30%MEDIUM2022-12-28

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

CVEs:CVE-2022-46174

Affected products

ProductStatusVendorPackageEcosystem
kubernetes-sigs/aws-efs-csi-driver affected github.com github.com/kubernetes-sigs/aws-efs-csi-driver
Upstream advisory

GHSA-v93c-cxj5-c398

GoogleCoalition ESS < 30%MEDIUM2022-12-12

Jenkins Google Login Plugin Open Redirect vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

GHSA-v93c-cxj5-c398

GoogleCoalition ESS < 30%MEDIUM2022-12-12

Jenkins Google Login Plugin Open Redirect vulnerability

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

CVE-2022-46683

GoogleCoalition ESS < 30%MEDIUM2022-12-07

Jenkins Google Login Plugin Open Redirect vulnerability

CVEs:CVE-2022-46683

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

CVE-2022-46683

GoogleCoalition ESS < 30%MEDIUM2022-12-07

Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

CVEs:CVE-2022-46683

Affected products

ProductStatusVendorPackageEcosystem
google_login affected jenkins
Upstream advisory

CVE-2022-4242

GoogleCoalition ESS < 30%CRITICAL2022-12-26

The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ...

CVEs:CVE-2022-4242

Affected products

ProductStatusVendorPackageEcosystem
wp_google_review_slider affected ljapps
Upstream advisory

CVE-2022-3840

GoogleCoalition ESS < 30%CRITICAL2022-12-26

The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d...

CVEs:CVE-2022-3840

Affected products

ProductStatusVendorPackageEcosystem
login_for_google_apps affected wp-glogin
Upstream advisory

ASB-A-253978054

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-253978054

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-29580

GoogleCoalition ESS < 30%CRITICAL2022-12-13

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can ...

CVEs:CVE-2022-29580

Affected products

ProductStatusVendorPackageEcosystem
google_search affected google
Upstream advisory

GHSA-gw62-c7w4-x449

Open SourceCoalition ESS < 30%CRITICAL2022-12-21

studygolang vulnerable to cross-site scripting

Affected products

ProductStatusVendorPackageEcosystem
studygolang/studygolang affected github.com github.com/studygolang/studygolang
Upstream advisory

GHSA-gw62-c7w4-x449

Open SourceCoalition ESS < 30%CRITICAL2022-12-21

studygolang vulnerable to cross-site scripting

Affected products

ProductStatusVendorPackageEcosystem
studygolang/studygolang affected github.com github.com/studygolang/studygolang
Upstream advisory

CVE-2021-4272

Open SourceCoalition ESS < 30%CRITICAL2022-12-21

A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static/js/topics.js. The manipulation of the argument contentHtml leads to cross site scripting. It is possible to initiate the attack rem...

CVEs:CVE-2021-4272

Affected products

ProductStatusVendorPackageEcosystem
studygolang affected studygolang
Upstream advisory

CVE-2021-4272

Open SourceCoalition ESS < 30%MEDIUM2022-12-21

studygolang vulnerable to cross-site scripting

CVEs:CVE-2021-4272

Affected products

ProductStatusVendorPackageEcosystem
studygolang/studygolang affected github.com github.com/studygolang/studygolang
Upstream advisory

CVE-2022-42768

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42768

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-228560539

GoogleCoalition ESS < 30%2022-12-01

PUB-A-228560539

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

PUB-A-238480163

GoogleCoalition ESS < 30%2022-12-01

PUB-A-238480163

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-4318

GoogleCoalition ESS < 30%HIGH2022-12-29

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVEs:CVE-2022-4318

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
extra_packages_for_enterprise_linux affected fedoraproject
fedora affected fedoraproject
openshift_container_platform_for_arm64 affected redhat
openshift_container_platform_for_linuxone affected redhat
openshift_container_platform_for_power affected redhat
openshift_container_platform_ibm_z_systems affected redhat
Upstream advisory

CVE-2022-4318

GoogleCoalition ESS < 30%MEDIUM2022-12-29

CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation

CVEs:CVE-2022-4318

Affected products

ProductStatusVendorPackageEcosystem
cri-o/cri-o affected github.com github.com/cri-o/cri-o
Upstream advisory

PUB-A-238479990

GoogleCoalition ESS < 30%2022-12-01

PUB-A-238479990

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20560

Open SourceCoalition ESS < 30%HIGH2022-12-05

Product: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/A

CVEs:CVE-2022-20560

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-212623833

GoogleCoalition ESS < 30%2022-12-01

PUB-A-212623833

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DEBIAN-CVE-2022-4123

Open SourceCoalition ESS < 30%HIGH2022-12-08

DEBIAN-CVE-2022-4123

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

CVE-2022-42535

Open SourceCoalition ESS < 30%HIGH2022-12-05

In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: And...

CVEs:CVE-2022-42535

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20513

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2022-20513

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42531

Open SourceCoalition ESS < 30%HIGH2022-12-05

In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2022-42531

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-231500967

GoogleCoalition ESS < 30%NONE2022-12-01

PUB-A-231500967

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-39900

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.

CVEs:CVE-2022-39900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20541

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: ...

CVEs:CVE-2022-20541

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20507

Open SourceCoalition ESS < 30%HIGH2022-12-05

In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...

CVEs:CVE-2022-20507

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20597

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ppmpu_set of ppmpu.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr...

CVEs:CVE-2022-20597

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-243480506

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-243480506

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20557

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2022-20557

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20562

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not n...

CVEs:CVE-2022-20562

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20576

Open SourceCoalition ESS < 30%HIGH2022-12-05

In externalOnRequest of rilapplication.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2022-20576

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20594

Open SourceCoalition ESS < 30%HIGH2022-12-05

In updateStart of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2022-20594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20599

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2022-20599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-231630423

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-231630423

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239567689

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-239567689

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239701761

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-239701761

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242332706

GoogleCoalition ESS < 30%NONE2022-12-01

PUB-A-242332706

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42521

Open SourceCoalition ESS < 30%HIGH2022-12-05

In encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...

CVEs:CVE-2022-42521

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42523

Open SourceCoalition ESS < 30%HIGH2022-12-05

In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...

CVEs:CVE-2022-42523

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42526

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ConvertUtf8ToUcs2 of radio_hal_utils.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2022-42526

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-243130019

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-243130019

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243376893

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-243376893

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-243509880

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-243509880

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20499

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2022-20499

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20555

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In ufdt_get_node_by_path_len of ufdt_convert.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20555

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20593

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In pop_descriptor_string of BufferDescriptor.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-20593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20595

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In getWpcAuthChallengeResponse of WirelessCharger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2022-20595

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-239415809

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-239415809

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-239700137

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-239700137

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42505

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User in...

CVEs:CVE-2022-42505

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42506

Open SourceCoalition ESS < 30%HIGH2022-12-05

In SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2022-42506

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241232492

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241232492

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241388399

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241388399

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20504

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In multiple locations of DreamManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and dismissal of system dialogs with User execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2022-20504

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20574

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In sec_sysmmu_info of drm_fw.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20574

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20575

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In read_ppmpu_info of drm_fw.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20575

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42534

Open SourceCoalition ESS < 30%HIGH2022-12-05

In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible privilege escalation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2022-42534

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-237582191

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-237582191

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-237585040

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-237585040

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-237838301

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-237838301

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20478

Open SourceCoalition ESS < 30%HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20479

Open SourceCoalition ESS < 30%HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20479

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20495

Open SourceCoalition ESS < 30%HIGH2022-12-05

In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges need...

CVEs:CVE-2022-20495

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42517

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In MiscService::DoOemSetTcsFci of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2022-42517

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241763682

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-241763682

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42507

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction ...

CVEs:CVE-2022-42507

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42508

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ProtocolCallBuilder::BuildSendUssd of protocolcallbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n...

CVEs:CVE-2022-42508

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42511

Open SourceCoalition ESS < 30%HIGH2022-12-05

In EmbmsSessionData::encode of embmsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2022-42511

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42530

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2022-42530

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241388774

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241388774

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241388966

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241388966

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241762712

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241762712

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-242331893

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-242331893

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20570

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

Product: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/A

CVEs:CVE-2022-20570

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-230660904

GoogleCoalition ESS < 30%2022-12-01

PUB-A-230660904

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42510

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In StringsRequestData::encode of requestdata.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2022-42510

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241762656

GoogleCoalition ESS < 30%NONE2022-12-01

PUB-A-241762656

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42516

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In ProtocolSimBuilderLegacy::BuildSimGetGbaAuth of protocolsimbuilderlegacy.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interac...

CVEs:CVE-2022-42516

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241763577

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-241763577

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42503

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User int...

CVEs:CVE-2022-42503

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42515

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In MiscService::DoOemSetRtpPktlossThreshold of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not neede...

CVEs:CVE-2022-42515

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241231983

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241231983

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-241763503

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-241763503

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20502

Open SourceCoalition ESS < 30%HIGH2022-12-05

In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2022-20502

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39091

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39091

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39092

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39092

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39090

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39090

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39102

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39102

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39099

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39099

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39100

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39100

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39101

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39101

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39094

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39094

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39095

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39095

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39096

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39096

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20556

Open SourceCoalition ESS < 30%LOW2022-12-05

In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution pri...

CVEs:CVE-2022-20556

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39098

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39098

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39097

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39097

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39904

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.

CVEs:CVE-2022-39904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20449

Open SourceCoalition ESS < 30%HIGH2022-12-05

In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. This could lead to local denial of service with System execution privileges needed. User interaction is not need...

CVEs:CVE-2022-20449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39906

Open SourceCoalition ESS < 30%LOW2022-12-08

Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.

CVEs:CVE-2022-39906

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20512

Open SourceCoalition ESS < 30%HIGH2022-12-05

In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...

CVEs:CVE-2022-20512

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39899

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

CVEs:CVE-2022-39899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32622

Open SourceCoalition ESS < 30%HIGH2022-12-05

In gz, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363786; Issue ID: ALP...

CVEs:CVE-2022-32622

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32630

Open SourceCoalition ESS < 30%HIGH2022-12-05

In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ...

CVEs:CVE-2022-32630

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32619

Open SourceCoalition ESS < 30%HIGH2022-12-05

In keyinstall, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07439659; ...

CVEs:CVE-2022-32619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-250441021

GoogleCoalition ESS < 30%HIGH2022-12-01

ASB-A-250441021

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-20501

Open SourceCoalition ESS < 30%HIGH2022-12-05

In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges...

CVEs:CVE-2022-20501

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42502

Open SourceCoalition ESS < 30%HIGH2022-12-05

In FacilityLock::Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2022-42502

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-241231970

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-241231970

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-32631

Open SourceCoalition ESS < 30%HIGH2022-12-05

In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453613; Issue...

CVEs:CVE-2022-32631

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-32632

Open SourceCoalition ESS < 30%HIGH2022-12-05

In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441630; Issue...

CVEs:CVE-2022-32632

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-42756

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-42756

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-253337348

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-253337348

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42776

Open SourceCoalition ESS < 30%HIGH2022-12-06

In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.

CVEs:CVE-2022-42776

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42777

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-42777

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39093

Open SourceCoalition ESS < 30%HIGH2022-12-06

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVEs:CVE-2022-39093

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20471

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2022-20471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-249998113

GoogleCoalition ESS < 30%MEDIUM2022-12-01

PUB-A-249998113

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42778

Open SourceCoalition ESS < 30%HIGH2022-12-06

In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.

CVEs:CVE-2022-42778

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20531

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...

CVEs:CVE-2022-20531

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39897

Open SourceCoalition ESS < 30%HIGH2022-12-08

Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.

CVEs:CVE-2022-39897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20475

Open SourceCoalition ESS < 30%HIGH2022-12-05

In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...

CVEs:CVE-2022-20475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39898

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.

CVEs:CVE-2022-39898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39907

Open SourceCoalition ESS < 30%HIGH2022-12-08

Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVEs:CVE-2022-39907

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39896

Open SourceCoalition ESS < 30%HIGH2022-12-08

Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

CVEs:CVE-2022-39896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-252398972

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-252398972

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-42779

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42779

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42780

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42781

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42773

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42774

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42761

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42761

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42762

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42762

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42763

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42763

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42764

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42764

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42759

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42759

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42760

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42760

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20487

Open SourceCoalition ESS < 30%HIGH2022-12-05

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2022-20487

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39106

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39106

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39129

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39130

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39130

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39132

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39132

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39133

Open SourceCoalition ESS < 30%HIGH2022-12-05

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-39133

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42754

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.

CVEs:CVE-2022-42754

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42755

Open SourceCoalition ESS < 30%HIGH2022-12-05

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-252943954

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-252943954

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-252950982

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-252950982

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-252950986

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-252950986

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-252951342

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-252951342

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-253344080

GoogleCoalition ESS < 30%HIGH2022-12-01

ASB-A-253344080

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-253957344

GoogleCoalition ESS < 30%2022-12-01

ASB-A-253957344

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-253957345

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-253957345

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2022-39905

Open SourceCoalition ESS < 30%HIGH2022-12-08

Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

CVEs:CVE-2022-39905

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39894

Open SourceCoalition ESS < 30%HIGH2022-12-08

Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

CVEs:CVE-2022-39894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39895

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.

CVEs:CVE-2022-39895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39914

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.

CVEs:CVE-2022-39914

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39903

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.

CVEs:CVE-2022-39903

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42769

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42769

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42765

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42765

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42757

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42757

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42758

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42758

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39912

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

CVEs:CVE-2022-39912

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42782

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

CVEs:CVE-2022-42782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20508

Open SourceCoalition ESS < 30%HIGH2022-12-05

In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2022-20508

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42772

Open SourceCoalition ESS < 30%HIGH2022-12-05

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42772

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39913

Open SourceCoalition ESS < 30%MEDIUM2022-12-08

Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.

CVEs:CVE-2022-39913

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42767

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42767

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42766

Open SourceCoalition ESS < 30%HIGH2022-12-06

In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

CVEs:CVE-2022-42766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20510

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the notification streaming policy of other users due to a permissions bypass. This could lead to local information disclosure with no add...

CVEs:CVE-2022-20510

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20544

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...

CVEs:CVE-2022-20544

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20567

Open SourceCoalition ESS < 30%HIGH2022-12-05

In pppol2tp_create of l2tp_ppp.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...

CVEs:CVE-2022-20567

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

PUB-A-186777253

GoogleCoalition ESS < 30%HIGH2022-12-01

PUB-A-186777253

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel: affected Android :linux_kernel:
Upstream advisory

CVE-2022-20558

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...

CVEs:CVE-2022-20558

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39908

Open SourceCoalition ESS < 30%HIGH2022-12-08

TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

CVEs:CVE-2022-39908

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32633

Open SourceCoalition ESS < 30%MEDIUM2022-12-05

In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; Issue ID: ALP...

CVEs:CVE-2022-32633

Affected products

ProductStatusVendorPackageEcosystem
android affected google
yocto affected yoctoproject
Upstream advisory

CVE-2022-32621

Open SourceCoalition ESS < 30%HIGH2022-12-05

In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310829; Issue ID: ALPS07...

CVEs:CVE-2022-32621

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32628

Open SourceCoalition ESS < 30%HIGH2022-12-05

In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310780; Issue ID: ...

CVEs:CVE-2022-32628

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32629

Open SourceCoalition ESS < 30%HIGH2022-12-05

In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310774; Issue ID: ...

CVEs:CVE-2022-32629

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32624

Open SourceCoalition ESS < 30%HIGH2022-12-05

In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ...

CVEs:CVE-2022-32624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32625

Open SourceCoalition ESS < 30%HIGH2022-12-05

In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326216; Iss...

CVEs:CVE-2022-32625

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32626

Open SourceCoalition ESS < 30%HIGH2022-12-05

In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326239; Iss...

CVEs:CVE-2022-32626

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-32634

Open SourceCoalition ESS < 30%HIGH2022-12-05

In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138646; Issue ...

CVEs:CVE-2022-32634

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20442

Open SourceCoalition ESS < 30%HIGH2022-12-05

In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges neede...

CVEs:CVE-2022-20442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42775

Open SourceCoalition ESS < 30%CRITICAL2022-12-06

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

CVEs:CVE-2022-42775

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39131

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39131

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-20611

Open SourceCoalition ESS < 30%HIGH2022-12-05

In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User int...

CVEs:CVE-2022-20611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-39134

Open SourceCoalition ESS < 30%CRITICAL2022-12-05

In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.

CVEs:CVE-2022-39134

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2022-42770

Open SourceCoalition ESS < 30%HIGH2022-12-05

In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.

CVEs:CVE-2022-42770

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-253333208

GoogleCoalition ESS < 30%HIGH2022-12-01

ASB-A-253333208

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-253978051

GoogleCoalition ESS < 30%CRITICAL2022-12-01

ASB-A-253978051

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2017-20155

GoogleEPSS <= 49%CRITICAL2022-12-30

A vulnerability was found in Sterc Google Analytics Dashboard for MODX up to 1.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file core/components/analyticsdashboardwidget/elements/tpl/widget...

CVEs:CVE-2017-20155

Affected products

ProductStatusVendorPackageEcosystem
google_analytics_dashboard_for_modx affected sterc
Upstream advisory

DEBIAN-CVE-2018-25060

Open SourceEPSS <= 49%HIGH2022-12-30

DEBIAN-CVE-2018-25060

Affected products

ProductStatusVendorPackageEcosystem
golang-github-go-macaron-csrf affected Debian:11 golang-github-go-macaron-csrf
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.