VDB

CVE-2022-20203

CVE-2022-20203 PUBLISHED CVSS 7.800000190734863 HIGH

In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding untrusted protobuf files. This could lead to local escalation of privilege,with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS 0.12% · 2.4th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
2.4th percentile

Affected Products

VendorProductVersions
n/aAndroidAndroid-12L
googleandroid12.1

Timeline

  • Jun 15, 2022 CVE Published
  • Jun 16, 2022 EPSS Score
  • Jun 28, 2022 EPSS Score
  • Aug 4, 2022 EPSS Score
  • Sep 21, 2022 EPSS Score
  • Nov 8, 2022 EPSS Score
  • Dec 27, 2022 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 20, 2023 EPSS Score
  • Jul 7, 2023 EPSS Score
  • Aug 24, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›