Advisories
Project ZeroExploitedCISA KEV listed2022-12-12
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CVEs:CVE-2022-42475
GoogleExploitedCISA KEV listedCRITICAL2022-12-12
CVEs:CVE-2022-42475
GoogleExploitedCISA KEV listedCRITICAL2022-12-12
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a...
CVEs:CVE-2022-42475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fortios |
affected |
fortinet |
— |
— |
| fortiproxy |
affected |
fortinet |
— |
— |
Open SourceExploitedCISA KEV listedHIGH2022-12-13
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-boynux-squid_exporter |
affected |
SUSE:Manager Client Tools 12 |
golang-github-boynux-squid_exporter |
— |
| grafana |
affected |
SUSE:Manager Client Tools 12 |
grafana |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools 12 |
prometheus-blackbox_exporter |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 12 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 12 |
spacewalk-client-tools |
— |
Open SourceExploitedCISA KEV listedHIGH2022-12-13
Security update for SUSE Manager Client Tools
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dracut-saltboot |
affected |
openSUSE:Leap 15.3 |
dracut-saltboot |
— |
| dracut-saltboot |
affected |
SUSE:Manager Client Tools 15 |
dracut-saltboot |
— |
| dracut-saltboot |
affected |
openSUSE:Leap 15.4 |
dracut-saltboot |
— |
| dracut-saltboot |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
dracut-saltboot |
— |
| golang-github-boynux-squid_exporter |
affected |
SUSE:Manager Proxy Module 4.3 |
golang-github-boynux-squid_exporter |
— |
| golang-github-boynux-squid_exporter |
affected |
openSUSE:Leap 15.4 |
golang-github-boynux-squid_exporter |
— |
| golang-github-boynux-squid_exporter |
affected |
SUSE:Manager Proxy Module 4.2 |
golang-github-boynux-squid_exporter |
— |
| golang-github-boynux-squid_exporter |
affected |
openSUSE:Leap 15.3 |
golang-github-boynux-squid_exporter |
— |
| golang-github-boynux-squid_exporter |
affected |
SUSE:Manager Client Tools 15 |
golang-github-boynux-squid_exporter |
— |
| golang-github-prometheus-promu |
affected |
openSUSE:Leap 15.3 |
golang-github-prometheus-promu |
— |
| golang-github-prometheus-promu |
affected |
openSUSE:Leap 15.4 |
golang-github-prometheus-promu |
— |
| grafana |
affected |
SUSE:Manager Client Tools 15 |
grafana |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Proxy Module 4.3 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools 15 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
SUSE:Manager Proxy Module 4.2 |
prometheus-blackbox_exporter |
— |
| prometheus-blackbox_exporter |
affected |
openSUSE:Leap 15.4 |
prometheus-blackbox_exporter |
— |
| spacecmd |
affected |
SUSE:Manager Client Tools 15 |
spacecmd |
— |
| spacecmd |
affected |
openSUSE:Leap 15.3 |
spacecmd |
— |
| spacecmd |
affected |
openSUSE:Leap 15.4 |
spacecmd |
— |
| spacewalk-client-tools |
affected |
SUSE:Manager Client Tools 15 |
spacewalk-client-tools |
— |
| uyuni-proxy-systemd-services |
affected |
SUSE:Manager Client Tools for SLE Micro 5 |
uyuni-proxy-systemd-services |
— |
| uyuni-proxy-systemd-services |
affected |
SUSE:Manager Client Tools 15 |
uyuni-proxy-systemd-services |
— |
| wire |
affected |
openSUSE:Leap 15.4 |
wire |
— |
Open SourceExploitedCISA KEV listedCRITICAL2022-12-06
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceExploitedCISA KEV listed2022-12-08
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceExploitedCISA KEV listed2022-12-04
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleExploitedCISA KEV listedHIGH2022-12-02
CVEs:CVE-2022-4262
GoogleExploitedCISA KEV listedHIGH2022-12-02
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceExploitedCISA KEV listedHIGH2022-12-02
DEBIAN-CVE-2022-4262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2022-12-02
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4262
GoogleExploitedCISA KEV listedHIGH2022-12-13
CVEs:CVE-2022-42856
Project ZeroExploitedCISA KEV listed2022-12-13
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
CVEs:CVE-2022-42856
GoogleExploitedCISA KEV listedCRITICAL2022-12-13
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execut...
CVEs:CVE-2022-42856
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
Project ZeroExploitedCISA KEV listed2022-12-13
Unauthenticated remote arbitrary code execution
CVEs:CVE-2022-27518
GoogleExploitedCISA KEV listedCRITICAL2022-12-13
Unauthenticated remote arbitrary code execution
CVEs:CVE-2022-27518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| application_delivery_controller_firmware |
affected |
citrix |
— |
— |
| gateway_firmware |
affected |
citrix |
— |
— |
GoogleExploitedCISA KEV listedCRITICAL2022-12-13
CVEs:CVE-2022-27518
Open SourceActive exploitation (sightings)HIGH2022-12-07
Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (python-XStatic-Angular) security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| python3-XStatic-Angular |
affected |
Red Hat:openstack:16.1::el8 |
python3-XStatic-Angular |
— |
| python-XStatic-Angular |
affected |
Red Hat:openstack:16.1::el8 |
python-XStatic-Angular |
— |
| XStatic-Angular-common |
affected |
Red Hat:openstack:16.1::el8 |
XStatic-Angular-common |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-07
Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.4 (python-XStatic-Angular) security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| python3-XStatic-Angular |
affected |
Red Hat:openstack:16.2::el8 |
python3-XStatic-Angular |
— |
| python-XStatic-Angular |
affected |
Red Hat:openstack:16.2::el8 |
python-XStatic-Angular |
— |
| XStatic-Angular-common |
affected |
Red Hat:openstack:16.2::el8 |
XStatic-Angular-common |
— |
Open SourceActive exploitation (sightings)NONE2022-12-17
kubernetes security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
openEuler:20.03-LTS-SP1 |
kubernetes |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20607
Open SourceActive exploitation (sightings)HIGH2022-12-05
In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: An...
CVEs:CVE-2022-20607
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-238914868
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20603
Open SourceActive exploitation (sightings)HIGH2022-12-05
In SetDecompContextDb of RohcDeCompContextOfRbId.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-219265339
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20606
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In SAEMM_MiningCodecTableWithMsgIE of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not nee...
CVEs:CVE-2022-20606
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-233230674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20516
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20516
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20605
Open SourceActive exploitation (sightings)HIGH2022-12-05
In SAECOMM_CopyBufferBytes of SAECOMM_Utility.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2022-20605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-231722405
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In sms_GetTpUdlIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-42524
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-42524
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-243401445
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In cellular modem firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2022-20610
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20610
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-240462530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20545
Open SourceActive exploitation (sightings)HIGH2022-12-05
In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2022-20545
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)CRITICAL2022-12-05
CVEs:CVE-2022-42529
Open SourceActive exploitation (sightings)CRITICAL2022-12-05
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
CVEs:CVE-2022-42529
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)2022-12-01
PUB-A-235292841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)CRITICAL2022-12-27
DEBIAN-CVE-2022-2582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-aws-aws-sdk-go |
affected |
Debian:11 |
golang-github-aws-aws-sdk-go |
— |
| golang-github-aws-aws-sdk-go |
affected |
Debian:12 |
golang-github-aws-aws-sdk-go |
— |
| golang-github-aws-aws-sdk-go |
affected |
Debian:13 |
golang-github-aws-aws-sdk-go |
— |
| golang-github-aws-aws-sdk-go |
affected |
Debian:14 |
golang-github-aws-aws-sdk-go |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVEs:CVE-2022-20530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20530
Open SourceActive exploitation (sightings)HIGH2022-12-05
Product: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/A
CVEs:CVE-2022-20601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20601
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20602
Open SourceActive exploitation (sightings)HIGH2022-12-05
Product: AndroidVersions: Android kernelAndroid ID: A-211081867References: N/A
CVEs:CVE-2022-20602
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)2022-12-01
PUB-A-204541506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)2022-12-01
PUB-A-211081867
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20604
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In SAECOMM_SetDcnIdForPlmn of SAECOMM_DbManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from a single device with no additional execution privileges needed. User inter...
CVEs:CVE-2022-20604
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-230463606
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVEs:CVE-2022-20474
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20474
Open SourceActive exploitation (sightings)HIGH2022-12-05
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20517
Open SourceActive exploitation (sightings)HIGH2022-12-05
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVEs:CVE-2022-20518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20518
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-220738351
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...
CVEs:CVE-2022-20520
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20520
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreen due to an incorrect state transition. This could lead to local information disclosure with physical access re...
CVEs:CVE-2022-20497
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20497
Open SourceActive exploitation (sightings)HIGH2022-12-05
In the Pixel camera driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2022-20581
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20581
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-245916120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2022-20591
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20591
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-238939706
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20540
Open SourceActive exploitation (sightings)HIGH2022-12-05
In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20540
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20598
Open SourceActive exploitation (sightings)HIGH2022-12-05
In sec_media_protect of media.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege of secure mode MFC Core with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20598
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20600
Open SourceActive exploitation (sightings)HIGH2022-12-05
In TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android...
CVEs:CVE-2022-20600
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-239847859
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-242357514
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20509
Open SourceActive exploitation (sightings)HIGH2022-12-05
In mapGrantorDescr of MessageQueueBase.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System ex...
CVEs:CVE-2022-20514
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20514
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20554
Open SourceActive exploitation (sightings)HIGH2022-12-05
In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2022-20554
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20563
Open SourceActive exploitation (sightings)HIGH2022-12-05
In TBD of ufdt_convert, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2022-20563
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In _ufdt_output_strtab_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2022-20564
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20564
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20569
Open SourceActive exploitation (sightings)HIGH2022-12-05
In thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interactio...
CVEs:CVE-2022-20569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-20571
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20571
Open SourceActive exploitation (sightings)HIGH2022-12-05
In OemSimAuthRequest::encode of wlandata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20577
Open SourceActive exploitation (sightings)HIGH2022-12-05
In RadioImpl::setGsmBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2022-20578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20578
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20579
Open SourceActive exploitation (sightings)HIGH2022-12-05
In RadioImpl::setCdmaBroadcastConfig of ril_service_legacy.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2022-20579
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20580
Open SourceActive exploitation (sightings)HIGH2022-12-05
In ufdt_do_one_fixup of ufdt_overlay.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-20580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20596
Open SourceActive exploitation (sightings)HIGH2022-12-05
In sendChunk of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Produc...
CVEs:CVE-2022-20596
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-229258234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-234030265
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-239700400
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-241762281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-242067561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-243509749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-243510139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-243629453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-243798789
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-42519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42519
Open SourceActive exploitation (sightings)HIGH2022-12-05
In ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe...
CVEs:CVE-2022-42520
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42520
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42525
Open SourceActive exploitation (sightings)HIGH2022-12-05
In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-42525
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-242540694
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-242994270
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-243509750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2022-20524
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20524
Open SourceActive exploitation (sightings)HIGH2022-12-05
In CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed ...
CVEs:CVE-2022-42504
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42504
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-241232209
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42522
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In DoSetCarrierConfig of miscservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2022-42522
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-243130038
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20480
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20480
Open SourceActive exploitation (sightings)HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20484
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20484
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed...
CVEs:CVE-2022-20515
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20515
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20590
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20590
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2022-20592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20592
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-238932493
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-238976908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20491
Open SourceActive exploitation (sightings)HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20491
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2022-42542
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42542
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for e...
CVEs:CVE-2022-20521
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20521
Open SourceActive exploitation (sightings)LOW2022-12-05
In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User int...
CVEs:CVE-2022-20529
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20529
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20543
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions...
CVEs:CVE-2022-20543
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In CallDialReqData::encode of callreqdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-42509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42509
Open SourceActive exploitation (sightings)HIGH2022-12-05
In ProtocolEmbmsBuilder::BuildSetSession of protocolembmsbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n...
CVEs:CVE-2022-42513
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42513
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42518
Open SourceActive exploitation (sightings)HIGH2022-12-05
In BroadcastSmsConfigsRequestData::encode of smsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2022-42518
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42532
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2022-42532
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-241544307
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-241763204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-242332610
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-242536278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In VsimOperationDataExt::encode of vsimdata.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-42512
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42512
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42514
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In ProtocolImsBuilder::BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not need...
CVEs:CVE-2022-42514
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-241763050
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-241763298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVEs:CVE-2022-20503
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20503
Open SourceActive exploitation (sightings)HIGH2022-12-05
In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVEs:CVE-2022-20506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20506
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In IncFs_GetFilledRangesStartingFrom of incfs.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2022-20523
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20523
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2022-20511
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20511
Open SourceActive exploitation (sightings)HIGH2022-12-05
In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2022-20522
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20522
Open SourceActive exploitation (sightings)HIGH2022-12-05
In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges neede...
CVEs:CVE-2022-20482
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20482
Open SourceActive exploitation (sightings)LOW2022-12-05
In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User int...
CVEs:CVE-2022-20519
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20519
Open SourceActive exploitation (sightings)HIGH2022-12-05
In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges need...
CVEs:CVE-2022-20477
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20477
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-32620
Open SourceActive exploitation (sightings)HIGH2022-12-05
In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07541753; Issue ID: ALPS07541753.
CVEs:CVE-2022-32620
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
ASB-A-250441023
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-32596
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-32597
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-32598
Open SourceActive exploitation (sightings)HIGH2022-12-05
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446213; Is...
CVEs:CVE-2022-32596
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Is...
CVEs:CVE-2022-32597
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446228; Is...
CVEs:CVE-2022-32598
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
ASB-A-250470696
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
ASB-A-250470697
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
ASB-A-250470698
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In HexString2Value of util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2022-42501
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42501
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-241231403
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitationProduct: An...
CVEs:CVE-2022-20505
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20505
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-32594
Open SourceActive exploitation (sightings)HIGH2022-12-05
In widevine, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446207; Is...
CVEs:CVE-2022-32594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
ASB-A-250331397
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2022-20496
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20496
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20553
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed f...
CVEs:CVE-2022-20553
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploita...
CVEs:CVE-2022-20526
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20526
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20548
Open SourceActive exploitation (sightings)HIGH2022-12-05
In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2022-20548
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20550
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20550
Open SourceActive exploitation (sightings)HIGH2022-12-05
In TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVEs:CVE-2022-20561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20561
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20584
Open SourceActive exploitation (sightings)HIGH2022-12-05
In page_number of shared_mem.c, there is a possible code execution in secure world due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20585
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20585
Open SourceActive exploitation (sightings)HIGH2022-12-05
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-20586
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20586
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20587
Open SourceActive exploitation (sightings)HIGH2022-12-05
In ppmp_validate_wsm of drm_fw.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2022-20587
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-222162870
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-238366009
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)NONE2022-12-01
PUB-A-238716781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)NONE2022-12-01
PUB-A-238718854
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)NONE2022-12-01
PUB-A-238720411
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-240919398
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| vendor/google/whitechapel/audio |
affected |
platform |
platform/vendor/google/whitechapel/audio |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In parameterToHal of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the audio server with System execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20539
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20539
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20549
Open SourceActive exploitation (sightings)HIGH2022-12-05
In authToken2AidlVec of KeyMintUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-20549
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20583
Open SourceActive exploitation (sightings)HIGH2022-12-05
In ppmp_unprotect_mfcfw_buf of drm_fw.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in S-EL1 with System execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20583
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In sysmmu_map of sysmmu.c, there is a possible EoP due to a precondition check failure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2022-20588
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20588
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-234859169
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)NONE2022-12-01
PUB-A-238785915
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)2022-12-01
PUB-A-235114749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel:Qualcomm |
affected |
Android |
:linux_kernel:Qualcomm |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20589
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In valid_va_secbuf_check of drm_access_control.c, there is a possible ID due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2022-20589
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-238841928
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2022-20546
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20546
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20199
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20199
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20485
Open SourceActive exploitation (sightings)HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20485
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20486
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20486
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20488
Open SourceActive exploitation (sightings)HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20488
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC firmware with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2022-20527
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20527
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional executi...
CVEs:CVE-2022-20538
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20538
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20552
Open SourceActive exploitation (sightings)HIGH2022-12-05
In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20552
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20608
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20608
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-20609
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In Pixel cellular firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A...
CVEs:CVE-2022-20609
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-239239246
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-01
PUB-A-239240808
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20528
Open SourceActive exploitation (sightings)LOW2022-12-05
In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2022-20528
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with...
CVEs:CVE-2022-20535
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20535
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20559
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no ad...
CVEs:CVE-2022-20559
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVEs:CVE-2022-20525
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20525
Open SourceActive exploitation (sightings)HIGH2022-12-05
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2022-20547
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20547
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20240
Open SourceActive exploitation (sightings)LOW2022-12-05
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is ...
CVEs:CVE-2022-20240
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20533
Open SourceActive exploitation (sightings)LOW2022-12-05
In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20533
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceActive exploitation (sightings)MEDIUM2022-12-05
In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVEs:CVE-2022-20536
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20536
Open SourceActive exploitation (sightings)LOW2022-12-05
In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive settings due to a missing permission check. This could lead to local escalation of privilege from the Guest user with no additional exec...
CVEs:CVE-2022-20537
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)LOW2022-12-05
CVEs:CVE-2022-20537
Open SourceActive exploitation (sightings)HIGH2022-12-05
In ppmp_unprotect_mfcfw_buf of drm_fw.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2022-20582
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2022-20582
GoogleActive exploitation (sightings)HIGH2022-12-01
PUB-A-233645166
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceActive exploitation (sightings)HIGH2022-12-05
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42771
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2022-12-05
CVEs:CVE-2022-42771
GoogleActive exploitation (sightings)CRITICAL2022-12-01
ASB-A-253978040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleActive exploitation (sightings)HIGH2022-12-05
CVEs:CVE-2021-39660
Open SourceActive exploitation (sightings)HIGH2022-12-05
In TBD of TBD, there is a possible way to archive arbitrary code execution in kernel due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2021-39660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2022-12-01
ASB-A-254742984
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourcePoC exploitCRITICAL2022-12-04
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourcePoC exploit2022-12-03
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourcePoC exploitHIGH2022-12-23
CVE-2022-43551 affecting package tensorflow for versions less than 2.16.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:3 |
tensorflow |
— |
Open SourcePoC exploitCRITICAL2022-12-05
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20473
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2022-12-05
CVEs:CVE-2022-20473
Open SourcePoC exploitCRITICAL2022-12-05
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20472
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitCRITICAL2022-12-05
CVEs:CVE-2022-20472
Open SourcePoC exploit2022-12-17
Updated golang packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Mageia:8 |
golang |
— |
Open SourcePoC exploitMEDIUM2022-12-08
golang.org/x/net/http2 vulnerable to possible excessive memory growth
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| x/net/http2 |
affected |
golang.org |
golang.org/x/net/http2 |
— |
Open SourcePoC exploitMEDIUM2022-12-08
golang.org/x/net/http2 vulnerable to possible excessive memory growth
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-1.19 |
affected |
chainguard |
go-1.19 |
— |
| go-1.19 |
affected |
wolfi |
go-1.19 |
— |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| x/net/http2 |
affected |
golang.org |
golang.org/x/net/http2 |
— |
| x/net/http2 |
affected |
golang.org |
— |
— |
Open SourcePoC exploitMEDIUM2022-12-08
CVE-2022-41717 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitMEDIUM2022-12-08
CVE-2022-41717 affecting package golang for versions less than 1.17.13-2,1.18.8-2,1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitMEDIUM2022-12-08
CVE-2022-41717 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitMEDIUM2022-12-08
CVE-2022-41717 affecting package golang for versions less than 1.21.6-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:2 |
golang |
— |
Open SourcePoC exploitMEDIUM2022-12-08
CVE-2022-41717 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
Open SourcePoC exploitMEDIUM2022-12-08
DEBIAN-CVE-2022-41717
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
| golang-golang-x-net |
affected |
Debian:11 |
golang-golang-x-net |
— |
| golang-golang-x-net |
affected |
Debian:12 |
golang-golang-x-net |
— |
| golang-golang-x-net |
affected |
Debian:13 |
golang-golang-x-net |
— |
| golang-golang-x-net |
affected |
Debian:14 |
golang-golang-x-net |
— |
Open SourcePoC exploit2022-12-08
Excessive memory growth in net/http and golang.org/x/net/http2
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow |
affected |
chainguard |
kubeflow |
— |
| kubeflow |
affected |
wolfi |
kubeflow |
— |
| kubeflow-fips |
affected |
chainguard |
kubeflow-fips |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| stdlib |
affected |
Go |
stdlib |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
Open SourcePoC exploitMEDIUM2022-12-08
golang.org/x/net/http2 vulnerable to possible excessive memory growth
CVEs:CVE-2022-41717
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/net |
affected |
golang.org |
golang.org/x/net |
— |
| x/net/http2 |
affected |
golang.org |
golang.org/x/net/http2 |
— |
GooglePoC exploitMEDIUM2022-12-08
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending ver...
CVEs:CVE-2022-41717
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
| http2 |
affected |
golang |
— |
— |
Open SourcePoC exploitCRITICAL2022-12-05
CVE-2022-32221 affecting package tensorflow for versions less than 2.16.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:3 |
tensorflow |
— |
Open SourcePoC exploitHIGH2022-12-05
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-20411
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-12-05
CVEs:CVE-2022-20411
Open SourcePoC exploitHIGH2022-12-05
CVE-2022-35260 affecting package tensorflow for versions less than 2.16.1-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| tensorflow |
affected |
Azure Linux:3 |
tensorflow |
— |
GooglePoC exploitHIGH2022-12-28
yaml package for Go can consume excessive amounts of CPU or memory
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| yaml.v2 |
affected |
gopkg.in |
gopkg.in/yaml.v2 |
— |
Open SourcePoC exploitHIGH2022-12-28
yaml package for Go can consume excessive amounts of CPU or memory
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| yaml.v2 |
affected |
gopkg.in |
gopkg.in/yaml.v2 |
— |
Open SourcePoC exploitHIGH2022-12-27
DEBIAN-CVE-2022-3064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-yaml.v2 |
affected |
Debian:11 |
golang-yaml.v2 |
— |
| golang-yaml.v2 |
affected |
Debian:12 |
golang-yaml.v2 |
— |
| golang-yaml.v2 |
affected |
Debian:13 |
golang-yaml.v2 |
— |
| golang-yaml.v2 |
affected |
Debian:14 |
golang-yaml.v2 |
— |
Open SourcePoC exploitHIGH2022-12-26
golang.org/x/text/language Out-of-bounds Read vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| dynamic-localpv-provisioner |
affected |
wolfi |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner |
affected |
chainguard |
dynamic-localpv-provisioner |
— |
| dynamic-localpv-provisioner-fips |
affected |
chainguard |
dynamic-localpv-provisioner-fips |
— |
| gitleaks |
affected |
wolfi |
gitleaks |
— |
| gitleaks |
affected |
chainguard |
gitleaks |
— |
| hey |
affected |
chainguard |
hey |
— |
| hey |
affected |
wolfi |
hey |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| prometheus-postgres-exporter-0.10 |
affected |
chainguard |
prometheus-postgres-exporter-0.10 |
— |
| terraform-provider-sendgrid |
affected |
wolfi |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid |
affected |
chainguard |
terraform-provider-sendgrid |
— |
| terraform-provider-sendgrid-fips |
affected |
chainguard |
terraform-provider-sendgrid-fips |
— |
| vt-cli |
affected |
wolfi |
vt-cli |
— |
| vt-cli |
affected |
chainguard |
vt-cli |
— |
| x/text |
affected |
golang.org |
golang.org/x/text |
— |
| x/text |
affected |
golang.org |
— |
— |
Open SourcePoC exploitHIGH2022-12-26
golang.org/x/text/language Out-of-bounds Read vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/text |
affected |
golang.org |
golang.org/x/text |
— |
Open SourcePoC exploitHIGH2022-12-26
DEBIAN-CVE-2021-38561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-golang-x-text |
affected |
Debian:11 |
golang-golang-x-text |
— |
| golang-golang-x-text |
affected |
Debian:12 |
golang-golang-x-text |
— |
| golang-golang-x-text |
affected |
Debian:13 |
golang-golang-x-text |
— |
| golang-golang-x-text |
affected |
Debian:14 |
golang-golang-x-text |
— |
Open SourcePoC exploitHIGH2022-12-07
CVE-2022-41720 affecting package golang 1.25.7-1
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Azure Linux:3 |
golang |
— |
GooglePoC exploitHIGH2022-12-07
CVEs:CVE-2022-41720
Open SourcePoC exploitHIGH2022-12-07
DEBIAN-CVE-2022-41720
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-1.15 |
affected |
Debian:11 |
golang-1.15 |
— |
| golang-1.19 |
affected |
Debian:12 |
golang-1.19 |
— |
GooglePoC exploitHIGH2022-12-07
On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For ex...
CVEs:CVE-2022-41720
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitHIGH2022-12-07
Restricted file access on Windows in os and net/http
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubeflow-katib |
affected |
wolfi |
kubeflow-katib |
— |
| kubeflow-katib |
affected |
chainguard |
kubeflow-katib |
— |
| stdlib |
affected |
Go |
stdlib |
— |
GooglePoC exploitMEDIUM2022-12-05
CVEs:CVE-2022-20498
Open SourcePoC exploitMEDIUM2022-12-05
In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2022-20498
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2022-12-12
Protobuf Java vulnerable to Uncontrolled Resource Consumption
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.protobuf:protobuf-java |
affected |
Maven |
com.google.protobuf:protobuf-java |
— |
| com.google.protobuf:protobuf-javalite |
affected |
Maven |
com.google.protobuf:protobuf-javalite |
— |
Open SourcePoC exploitCRITICAL2022-12-12
Protobuf Java vulnerable to Uncontrolled Resource Consumption
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| celeborn-0.5 |
affected |
chainguard |
celeborn-0.5 |
— |
| celeborn-0.5 |
affected |
wolfi |
celeborn-0.5 |
— |
| celeborn-0.6 |
affected |
wolfi |
celeborn-0.6 |
— |
| celeborn-0.6 |
affected |
chainguard |
celeborn-0.6 |
— |
| com.google.protobuf:protobuf-java |
affected |
Maven |
com.google.protobuf:protobuf-java |
— |
| com.google.protobuf:protobuf-javalite |
affected |
Maven |
com.google.protobuf:protobuf-javalite |
— |
| dotty |
affected |
wolfi |
dotty |
— |
| dotty |
affected |
chainguard |
dotty |
— |
| druid |
affected |
wolfi |
druid |
— |
| druid |
affected |
chainguard |
druid |
— |
| emsdk |
affected |
chainguard |
emsdk |
— |
| hadoop-client-modules |
affected |
chainguard |
hadoop-client-modules |
— |
| spark-3.5.0-compat |
affected |
chainguard |
spark-3.5.0-compat |
— |
| trino |
affected |
chainguard |
trino |
— |
| trino |
affected |
wolfi |
trino |
— |
Open SourcePoC exploitHIGH2022-12-12
DEBIAN-CVE-2022-3509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
Debian:11 |
protobuf |
— |
| protobuf |
affected |
Debian:12 |
protobuf |
— |
| protobuf |
affected |
Debian:13 |
protobuf |
— |
| protobuf |
affected |
Debian:14 |
protobuf |
— |
GooglePoC exploit2022-12-01
PUB-A-233438137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploit2022-12-09
kubernetes security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
openEuler:20.03-LTS-SP1 |
kubernetes |
— |
| kubernetes |
affected |
openEuler:20.03-LTS-SP3 |
kubernetes |
— |
| kubernetes |
affected |
openEuler:22.03-LTS |
kubernetes |
— |
Open SourcePoC exploitCRITICAL2022-12-12
Protobuf Java vulnerable to Uncontrolled Resource Consumption
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| celeborn-0.5 |
affected |
chainguard |
celeborn-0.5 |
— |
| celeborn-0.5 |
affected |
wolfi |
celeborn-0.5 |
— |
| celeborn-0.6 |
affected |
wolfi |
celeborn-0.6 |
— |
| celeborn-0.6 |
affected |
chainguard |
celeborn-0.6 |
— |
| com.google.protobuf:protobuf-java |
affected |
Maven |
com.google.protobuf:protobuf-java |
— |
| com.google.protobuf:protobuf-javalite |
affected |
Maven |
com.google.protobuf:protobuf-javalite |
— |
| dotty |
affected |
wolfi |
dotty |
— |
| dotty |
affected |
chainguard |
dotty |
— |
| druid |
affected |
wolfi |
druid |
— |
| druid |
affected |
chainguard |
druid |
— |
| emsdk |
affected |
chainguard |
emsdk |
— |
| hadoop-client-modules |
affected |
chainguard |
hadoop-client-modules |
— |
| spark-3.5.0-compat |
affected |
chainguard |
spark-3.5.0-compat |
— |
| trino |
affected |
chainguard |
trino |
— |
| trino |
affected |
wolfi |
trino |
— |
Open SourcePoC exploitCRITICAL2022-12-12
Protobuf Java vulnerable to Uncontrolled Resource Consumption
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.protobuf:protobuf-java |
affected |
Maven |
com.google.protobuf:protobuf-java |
— |
| com.google.protobuf:protobuf-javalite |
affected |
Maven |
com.google.protobuf:protobuf-javalite |
— |
Open SourcePoC exploitHIGH2022-12-12
DEBIAN-CVE-2022-3510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
Debian:11 |
protobuf |
— |
| protobuf |
affected |
Debian:12 |
protobuf |
— |
| protobuf |
affected |
Debian:13 |
protobuf |
— |
| protobuf |
affected |
Debian:14 |
protobuf |
— |
Open SourcePoC exploitCRITICAL2022-12-27
DEBIAN-CVE-2017-20146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-gorilla-handlers |
affected |
Debian:12 |
golang-github-gorilla-handlers |
— |
| golang-github-gorilla-handlers |
affected |
Debian:11 |
golang-github-gorilla-handlers |
— |
| golang-github-gorilla-handlers |
affected |
Debian:13 |
golang-github-gorilla-handlers |
— |
| golang-github-gorilla-handlers |
affected |
Debian:14 |
golang-github-gorilla-handlers |
— |
GooglePoC exploitHIGH2022-12-05
CVEs:CVE-2022-20483
Open SourcePoC exploitHIGH2022-12-05
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User i...
CVEs:CVE-2022-20483
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2022-12-01
PUB-A-234020136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitMEDIUM2022-12-01
ASB-A-215557547
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitNONE2022-12-01
PUB-A-234475629
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitCRITICAL2022-12-28
YAML Go package vulnerable to denial of service
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| go-yaml/yaml |
affected |
github.com |
github.com/go-yaml/yaml |
— |
| yaml.v2 |
affected |
gopkg.in |
gopkg.in/yaml.v2 |
— |
Open SourcePoC exploitCRITICAL2022-12-28
YAML Go package vulnerable to denial of service
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| dex-k8s-authenticator |
affected |
chainguard |
dex-k8s-authenticator |
— |
| go-yaml/yaml |
affected |
github.com |
github.com/go-yaml/yaml |
— |
| k3d |
affected |
chainguard |
k3d |
— |
| k3d |
affected |
wolfi |
k3d |
— |
| yaml.v2 |
affected |
gopkg.in |
gopkg.in/yaml.v2 |
— |
Open SourcePoC exploitCRITICAL2022-12-27
DEBIAN-CVE-2021-4235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-yaml.v2 |
affected |
Debian:11 |
golang-yaml.v2 |
— |
| golang-yaml.v2 |
affected |
Debian:12 |
golang-yaml.v2 |
— |
| golang-yaml.v2 |
affected |
Debian:13 |
golang-yaml.v2 |
— |
| golang-yaml.v2 |
affected |
Debian:14 |
golang-yaml.v2 |
— |
GooglePoC exploit2022-12-01
PUB-A-228694391
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploit2022-12-01
PUB-A-235183128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploit2022-12-01
PUB-A-235540888
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GooglePoC exploitHIGH2022-12-01
PUB-A-160818461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploitHIGH2022-12-05
In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not nee...
CVEs:CVE-2022-20469
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-12-05
CVEs:CVE-2022-20469
Open SourcePoC exploitHIGH2022-12-05
In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVEs:CVE-2022-20470
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2022-12-05
CVEs:CVE-2022-20470
GooglePoC exploitHIGH2022-12-01
PUB-A-165329981
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourcePoC exploitHIGH2022-12-05
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction ...
CVEs:CVE-2022-20476
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2022-12-05
CVEs:CVE-2022-20476
Open SourcePoC exploitMEDIUM2022-12-05
In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2022-20468
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2022-12-05
CVEs:CVE-2022-20468
Open SourcePoC exploitMEDIUM2022-12-05
In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVEs:CVE-2022-20500
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2022-12-05
CVEs:CVE-2022-20500
GooglePoC exploitMEDIUM2022-12-05
CVEs:CVE-2022-20466
Open SourcePoC exploitMEDIUM2022-12-05
In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional exec...
CVEs:CVE-2022-20466
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVEs:CVE-2022-44708
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge |
affected |
microsoft |
— |
— |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-44708
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-41115
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
CVEs:CVE-2022-41115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-27
DEBIAN-CVE-2020-36568
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-revel-revel |
affected |
Debian:11 |
golang-github-revel-revel |
— |
| golang-github-revel-revel |
affected |
Debian:12 |
golang-github-revel-revel |
— |
| golang-github-revel-revel |
affected |
Debian:13 |
golang-github-revel-revel |
— |
| golang-github-revel-revel |
affected |
Debian:14 |
golang-github-revel-revel |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-27
DEBIAN-CVE-2020-36567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-gin-gonic-gin |
affected |
Debian:11 |
golang-github-gin-gonic-gin |
— |
| golang-github-gin-gonic-gin |
affected |
Debian:12 |
golang-github-gin-gonic-gin |
— |
| golang-github-gin-gonic-gin |
affected |
Debian:13 |
golang-github-gin-gonic-gin |
— |
| golang-github-gin-gonic-gin |
affected |
Debian:14 |
golang-github-gin-gonic-gin |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-44688
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVEs:CVE-2022-44688
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| edge_chromium |
affected |
microsoft |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-25
CVEs:CVE-2020-36628
Open SourceCoalition ESS < 30%CRITICAL2022-12-25
A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to...
CVEs:CVE-2020-36628
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android_processing_development_environment |
affected |
android_processing_development_environment_project |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-08
DEBIAN-CVE-2022-4122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-containers-buildah |
affected |
Debian:11 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:12 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:13 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:14 |
golang-github-containers-buildah |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion...
CVEs:CVE-2022-42527
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-42527
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-244448906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-28
golang-nanoauth authentication bypass vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| nanobox-io/golang-nanoauth |
affected |
github.com |
github.com/nanobox-io/golang-nanoauth |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-28
golang-nanoauth authentication bypass vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| nanobox-io/golang-nanoauth |
affected |
github.com |
github.com/nanobox-io/golang-nanoauth |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-27
golang-nanoauth authentication bypass vulnerability
CVEs:CVE-2020-36569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| nanobox-io/golang-nanoauth |
affected |
github.com |
github.com/nanobox-io/golang-nanoauth |
— |
Open SourceCoalition ESS < 30%CRITICAL2021-04-14
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
CVEs:CVE-2020-36569
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-nanoauth |
affected |
digitalocean |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-27
AWS SDK is vulnerable to server-side request forgery (SSRF)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.amazonaws:aws-android-sdk-mobile-client |
affected |
Maven |
com.amazonaws:aws-android-sdk-mobile-client |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-27
AWS SDK is vulnerable to server-side request forgery (SSRF)
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.amazonaws:aws-android-sdk-mobile-client |
affected |
Maven |
com.amazonaws:aws-android-sdk-mobile-client |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-24
A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-core/src/main/java/com/amazonaws/util/XpathUtils.java of the component XML Parser. The manipulation leads...
CVEs:CVE-2022-4725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| aws_software_development_kit |
affected |
amazon |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-24
AWS SDK is vulnerable to server-side request forgery (SSRF)
CVEs:CVE-2022-4725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.amazonaws:aws-android-sdk-mobile-client |
affected |
Maven |
com.amazonaws:aws-android-sdk-mobile-client |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-24
Updated chromium-browser-stable packages fix security vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:8 |
chromium-browser-stable |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-16
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.3 |
chromium |
— |
| chromium |
affected |
SUSE:Package Hub 15 SP3 |
— |
— |
Open SourceCoalition ESS < 30%2022-12-16
chromium - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP4 |
chromium |
— |
| chromium |
affected |
openSUSE:Leap 15.4 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-14
DEBIAN-CVE-2022-4437
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-14
DEBIAN-CVE-2022-4438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-13
Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4437
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-13
CVEs:CVE-2022-4437
GoogleCoalition ESS < 30%CRITICAL2022-12-13
Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: ...
CVEs:CVE-2022-4438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-13
CVEs:CVE-2022-4438
Open SourceCoalition ESS < 30%CRITICAL2022-12-14
DEBIAN-CVE-2022-4436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-13
Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2022-4436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-13
CVEs:CVE-2022-4436
Open SourceCoalition ESS < 30%CRITICAL2022-12-14
DEBIAN-CVE-2022-4440
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-13
Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2022-4440
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-13
CVEs:CVE-2022-4440
Open SourceCoalition ESS < 30%CRITICAL2022-12-14
DEBIAN-CVE-2022-4439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2022-12-13
CVEs:CVE-2022-4439
GoogleCoalition ESS < 30%CRITICAL2022-12-13
Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security se...
CVEs:CVE-2022-4439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-25
DEBIAN-CVE-2020-36627
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-go-macaron-i18n |
affected |
Debian:11 |
golang-github-go-macaron-i18n |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-30
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-sigs/aws-efs-csi-driver |
affected |
github.com |
github.com/kubernetes-sigs/aws-efs-csi-driver |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-30
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-sigs/aws-efs-csi-driver |
affected |
github.com |
github.com/kubernetes-sigs/aws-efs-csi-driver |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-28
efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a...
CVEs:CVE-2022-46174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| efs-utils |
affected |
amazon |
— |
— |
| elastic_file_system_container_storage_interface_driver |
affected |
amazon |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-28
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
CVEs:CVE-2022-46174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-sigs/aws-efs-csi-driver |
affected |
github.com |
github.com/kubernetes-sigs/aws-efs-csi-driver |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-28
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
CVEs:CVE-2022-46174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes-sigs/aws-efs-csi-driver |
affected |
github.com |
github.com/kubernetes-sigs/aws-efs-csi-driver |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-12
Jenkins Google Login Plugin Open Redirect vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-12
Jenkins Google Login Plugin Open Redirect vulnerability
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-07
Jenkins Google Login Plugin Open Redirect vulnerability
CVEs:CVE-2022-46683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.jenkins-ci.plugins:google-login |
affected |
Maven |
org.jenkins-ci.plugins:google-login |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-07
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
CVEs:CVE-2022-46683
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_login |
affected |
jenkins |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-26
The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ...
CVEs:CVE-2022-4242
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| wp_google_review_slider |
affected |
ljapps |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-26
CVEs:CVE-2022-4242
GoogleCoalition ESS < 30%MEDIUM2022-12-26
CVEs:CVE-2022-3840
GoogleCoalition ESS < 30%CRITICAL2022-12-26
The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d...
CVEs:CVE-2022-3840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| login_for_google_apps |
affected |
wp-glogin |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-253978054
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-13
There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can ...
CVEs:CVE-2022-29580
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_search |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-13
CVEs:CVE-2022-29580
Open SourceCoalition ESS < 30%CRITICAL2022-12-21
studygolang vulnerable to cross-site scripting
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| studygolang/studygolang |
affected |
github.com |
github.com/studygolang/studygolang |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-21
studygolang vulnerable to cross-site scripting
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| studygolang/studygolang |
affected |
github.com |
github.com/studygolang/studygolang |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-21
A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static/js/topics.js. The manipulation of the argument contentHtml leads to cross site scripting. It is possible to initiate the attack rem...
CVEs:CVE-2021-4272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| studygolang |
affected |
studygolang |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-21
studygolang vulnerable to cross-site scripting
CVEs:CVE-2021-4272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| studygolang/studygolang |
affected |
github.com |
github.com/studygolang/studygolang |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42768
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42768
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-12-01
PUB-A-228560539
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%2022-12-01
PUB-A-238480163
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-29
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
CVEs:CVE-2022-4318
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o |
affected |
kubernetes |
— |
— |
| extra_packages_for_enterprise_linux |
affected |
fedoraproject |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| openshift_container_platform_for_arm64 |
affected |
redhat |
— |
— |
| openshift_container_platform_for_linuxone |
affected |
redhat |
— |
— |
| openshift_container_platform_for_power |
affected |
redhat |
— |
— |
| openshift_container_platform_ibm_z_systems |
affected |
redhat |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-29
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
CVEs:CVE-2022-4318
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cri-o/cri-o |
affected |
github.com |
github.com/cri-o/cri-o |
— |
GoogleCoalition ESS < 30%2022-12-01
PUB-A-238479990
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
Product: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/A
CVEs:CVE-2022-20560
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20560
GoogleCoalition ESS < 30%2022-12-01
PUB-A-212623833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-08
DEBIAN-CVE-2022-4123
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-containers-buildah |
affected |
Debian:11 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:12 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:13 |
golang-github-containers-buildah |
— |
| golang-github-containers-buildah |
affected |
Debian:14 |
golang-github-containers-buildah |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42535
Open SourceCoalition ESS < 30%HIGH2022-12-05
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVEs:CVE-2022-42535
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2022-20513
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20513
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-42531
Open SourceCoalition ESS < 30%HIGH2022-12-05
In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2022-42531
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2022-12-01
PUB-A-231500967
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-08
CVEs:CVE-2022-39900
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.
CVEs:CVE-2022-39900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20541
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: ...
CVEs:CVE-2022-20541
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVEs:CVE-2022-20507
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20507
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20597
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ppmpu_set of ppmpu.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr...
CVEs:CVE-2022-20597
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-243480506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...
CVEs:CVE-2022-20557
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20557
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not n...
CVEs:CVE-2022-20562
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-05
CVEs:CVE-2022-20562
Open SourceCoalition ESS < 30%HIGH2022-12-05
In externalOnRequest of rilapplication.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2022-20576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20576
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20594
Open SourceCoalition ESS < 30%HIGH2022-12-05
In updateStart of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2022-20594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2022-20599
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20599
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-231630423
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-239567689
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-239701761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%NONE2022-12-01
PUB-A-242332706
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2022-42521
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42521
Open SourceCoalition ESS < 30%HIGH2022-12-05
In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for...
CVEs:CVE-2022-42523
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42523
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42526
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ConvertUtf8ToUcs2 of radio_hal_utils.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2022-42526
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-243130019
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-243376893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-243509880
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVEs:CVE-2022-20499
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20499
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20555
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In ufdt_get_node_by_path_len of ufdt_convert.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20593
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In pop_descriptor_string of BufferDescriptor.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-20593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20595
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In getWpcAuthChallengeResponse of WirelessCharger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2022-20595
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-239415809
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-239700137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User in...
CVEs:CVE-2022-42505
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42505
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42506
Open SourceCoalition ESS < 30%HIGH2022-12-05
In SimUpdatePbEntry::encode of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2022-42506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241232492
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241388399
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In multiple locations of DreamManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and dismissal of system dialogs with User execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2022-20504
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20504
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In sec_sysmmu_info of drm_fw.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20574
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In read_ppmpu_info of drm_fw.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20575
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20575
Open SourceCoalition ESS < 30%HIGH2022-12-05
In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible privilege escalation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVEs:CVE-2022-42534
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-42534
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-237582191
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-237585040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-237838301
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20478
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20478
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20479
Open SourceCoalition ESS < 30%HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20479
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges need...
CVEs:CVE-2022-20495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20495
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In MiscService::DoOemSetTcsFci of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2022-42517
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42517
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-241763682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42507
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction ...
CVEs:CVE-2022-42507
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ProtocolCallBuilder::BuildSendUssd of protocolcallbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n...
CVEs:CVE-2022-42508
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42508
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42511
Open SourceCoalition ESS < 30%HIGH2022-12-05
In EmbmsSessionData::encode of embmsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2022-42511
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2022-42530
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42530
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241388774
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241388966
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241762712
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-242331893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20570
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
Product: AndroidVersions: Android kernelAndroid ID: A-230660904References: N/A
CVEs:CVE-2022-20570
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2022-12-01
PUB-A-230660904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42510
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In StringsRequestData::encode of requestdata.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2022-42510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%NONE2022-12-01
PUB-A-241762656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In ProtocolSimBuilderLegacy::BuildSimGetGbaAuth of protocolsimbuilderlegacy.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interac...
CVEs:CVE-2022-42516
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42516
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-241763577
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42503
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User int...
CVEs:CVE-2022-42503
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In MiscService::DoOemSetRtpPktlossThreshold of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not neede...
CVEs:CVE-2022-42515
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42515
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241231983
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-241763503
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20502
Open SourceCoalition ESS < 30%HIGH2022-12-05
In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2022-20502
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39091
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39091
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39092
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39092
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39090
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39090
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39102
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39102
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39099
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39099
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39100
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39101
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39101
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39094
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39094
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39095
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39095
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39096
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39096
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%LOW2022-12-05
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution pri...
CVEs:CVE-2022-20556
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-05
CVEs:CVE-2022-20556
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39098
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39098
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39097
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39097
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.
CVEs:CVE-2022-39904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39904
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20449
Open SourceCoalition ESS < 30%HIGH2022-12-05
In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. This could lead to local denial of service with System execution privileges needed. User interaction is not need...
CVEs:CVE-2022-20449
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%LOW2022-12-08
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.
CVEs:CVE-2022-39906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39906
Open SourceCoalition ESS < 30%HIGH2022-12-05
In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVEs:CVE-2022-20512
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20512
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
CVEs:CVE-2022-39899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-08
CVEs:CVE-2022-39899
Open SourceCoalition ESS < 30%HIGH2022-12-05
In gz, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363786; Issue ID: ALP...
CVEs:CVE-2022-32622
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32622
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32630
Open SourceCoalition ESS < 30%HIGH2022-12-05
In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ...
CVEs:CVE-2022-32630
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32619
Open SourceCoalition ESS < 30%HIGH2022-12-05
In keyinstall, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07439659; ...
CVEs:CVE-2022-32619
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
ASB-A-250441021
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges...
CVEs:CVE-2022-20501
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20501
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42502
Open SourceCoalition ESS < 30%HIGH2022-12-05
In FacilityLock::Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2022-42502
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-241231970
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453613; Issue...
CVEs:CVE-2022-32631
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
yoctoproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32631
Open SourceCoalition ESS < 30%HIGH2022-12-05
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441630; Issue...
CVEs:CVE-2022-32632
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
yoctoproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32632
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42756
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.
CVEs:CVE-2022-42756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-253337348
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-42776
Open SourceCoalition ESS < 30%HIGH2022-12-06
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.
CVEs:CVE-2022-42776
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-42777
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-42777
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-39093
Open SourceCoalition ESS < 30%HIGH2022-12-06
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
CVEs:CVE-2022-39093
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20471
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2022-20471
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-01
PUB-A-249998113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.
CVEs:CVE-2022-42778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-06
CVEs:CVE-2022-42778
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User in...
CVEs:CVE-2022-20531
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-05
CVEs:CVE-2022-20531
GoogleCoalition ESS < 30%MEDIUM2022-12-08
CVEs:CVE-2022-39897
Open SourceCoalition ESS < 30%HIGH2022-12-08
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.
CVEs:CVE-2022-39897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVEs:CVE-2022-20475
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20475
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39898
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
CVEs:CVE-2022-39898
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-08
Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.
CVEs:CVE-2022-39907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-08
CVEs:CVE-2022-39907
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39896
Open SourceCoalition ESS < 30%HIGH2022-12-08
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
CVEs:CVE-2022-39896
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-252398972
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42779
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42779
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42780
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42781
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42773
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42773
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42774
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42774
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42761
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42762
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42763
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42764
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42759
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42760
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42760
Open SourceCoalition ESS < 30%HIGH2022-12-05
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2022-20487
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20487
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39106
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVEs:CVE-2022-39106
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39129
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVEs:CVE-2022-39129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39130
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVEs:CVE-2022-39130
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVEs:CVE-2022-39132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39132
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39133
Open SourceCoalition ESS < 30%HIGH2022-12-05
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-39133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.
CVEs:CVE-2022-42754
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42754
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42755
Open SourceCoalition ESS < 30%HIGH2022-12-05
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-252943954
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-252950982
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-252950986
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-252951342
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
ASB-A-253344080
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%2022-12-01
ASB-A-253957344
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-253957345
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-08
CVEs:CVE-2022-39905
Open SourceCoalition ESS < 30%HIGH2022-12-08
Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.
CVEs:CVE-2022-39905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-08
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
CVEs:CVE-2022-39894
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39894
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.
CVEs:CVE-2022-39895
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39895
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39914
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.
CVEs:CVE-2022-39914
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
CVEs:CVE-2022-39903
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39903
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42769
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-06
CVEs:CVE-2022-42769
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42765
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42765
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-06
CVEs:CVE-2022-42757
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-06
CVEs:CVE-2022-42758
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
CVEs:CVE-2022-39912
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39912
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42782
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
CVEs:CVE-2022-42782
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20508
Open SourceCoalition ESS < 30%HIGH2022-12-05
In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVEs:CVE-2022-20508
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42772
Open SourceCoalition ESS < 30%HIGH2022-12-05
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-08
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.
CVEs:CVE-2022-39913
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-08
CVEs:CVE-2022-39913
GoogleCoalition ESS < 30%LOW2022-12-06
CVEs:CVE-2022-42767
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42766
Open SourceCoalition ESS < 30%HIGH2022-12-06
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
CVEs:CVE-2022-42766
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the notification streaming policy of other users due to a permissions bypass. This could lead to local information disclosure with no add...
CVEs:CVE-2022-20510
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20510
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVEs:CVE-2022-20544
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20544
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-20567
Open SourceCoalition ESS < 30%HIGH2022-12-05
In pppol2tp_create of l2tp_ppp.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...
CVEs:CVE-2022-20567
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
PUB-A-186777253
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :linux_kernel: |
affected |
Android |
:linux_kernel: |
— |
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVEs:CVE-2022-20558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2022-12-05
CVEs:CVE-2022-20558
Open SourceCoalition ESS < 30%HIGH2022-12-08
TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.
CVEs:CVE-2022-39908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-08
CVEs:CVE-2022-39908
Open SourceCoalition ESS < 30%MEDIUM2022-12-05
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; Issue ID: ALP...
CVEs:CVE-2022-32633
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| yocto |
affected |
yoctoproject |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32633
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32621
Open SourceCoalition ESS < 30%HIGH2022-12-05
In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310829; Issue ID: ALPS07...
CVEs:CVE-2022-32621
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32628
Open SourceCoalition ESS < 30%HIGH2022-12-05
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310780; Issue ID: ...
CVEs:CVE-2022-32628
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310774; Issue ID: ...
CVEs:CVE-2022-32629
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32629
Open SourceCoalition ESS < 30%HIGH2022-12-05
In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ...
CVEs:CVE-2022-32624
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32624
Open SourceCoalition ESS < 30%HIGH2022-12-05
In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326216; Iss...
CVEs:CVE-2022-32625
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32625
Open SourceCoalition ESS < 30%HIGH2022-12-05
In display, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326239; Iss...
CVEs:CVE-2022-32626
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32626
Open SourceCoalition ESS < 30%HIGH2022-12-05
In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138646; Issue ...
CVEs:CVE-2022-32634
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-32634
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20442
Open SourceCoalition ESS < 30%HIGH2022-12-05
In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges neede...
CVEs:CVE-2022-20442
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2022-12-06
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
CVEs:CVE-2022-42775
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-06
CVEs:CVE-2022-42775
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39131
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
CVEs:CVE-2022-39131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2022-12-05
In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User int...
CVEs:CVE-2022-20611
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-05
CVEs:CVE-2022-20611
Open SourceCoalition ESS < 30%CRITICAL2022-12-05
In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.
CVEs:CVE-2022-39134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-39134
GoogleCoalition ESS < 30%MEDIUM2022-12-05
CVEs:CVE-2022-42770
Open SourceCoalition ESS < 30%HIGH2022-12-05
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
CVEs:CVE-2022-42770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2022-12-01
ASB-A-253333208
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleCoalition ESS < 30%CRITICAL2022-12-01
ASB-A-253978051
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| :unknown: |
affected |
Android |
:unknown: |
— |
GoogleEPSS <= 49%MEDIUM2022-12-30
CVEs:CVE-2017-20155
GoogleEPSS <= 49%CRITICAL2022-12-30
A vulnerability was found in Sterc Google Analytics Dashboard for MODX up to 1.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file core/components/analyticsdashboardwidget/elements/tpl/widget...
CVEs:CVE-2017-20155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_analytics_dashboard_for_modx |
affected |
sterc |
— |
— |
Open SourceEPSS <= 49%HIGH2022-12-30
DEBIAN-CVE-2018-25060
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-go-macaron-csrf |
affected |
Debian:11 |
golang-github-go-macaron-csrf |
— |