VDB
CVE-2022-20203
CVE-2022-20203
PUBLISHED
CVSS 7.800000190734863 HIGH
In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding untrusted protobuf files. This could lead to local escalation of privilege,with no additional execution privileges needed. User interaction is not needed for exploitation.
EPSS 0.12% · 2.4th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
2.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Android | Android-12L |
| android | 12.1 |
Timeline
- Jun 15, 2022 CVE Published
- Jun 16, 2022 EPSS Score
- Jun 28, 2022 EPSS Score
- Aug 4, 2022 EPSS Score
- Sep 21, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Dec 27, 2022 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 20, 2023 EPSS Score
- Jul 7, 2023 EPSS Score
- Aug 24, 2023 EPSS Score