CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2022-20589

    Last Modified: 18 Apr 2025

    In valid_va_secbuf_check of drm_access_control.c, there is a possible ID due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238841928References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20592

    Last Modified: 18 Apr 2025

    In ppmp_validate_secbuf of drm_fw.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238976908References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-20593

    Last Modified: 18 Apr 2025

    In pop_descriptor_string of BufferDescriptor.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239415809References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20594

    Last Modified: 18 Apr 2025

    In updateStart of WirelessCharger.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239567689References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-20595

    Last Modified: 18 Apr 2025

    In getWpcAuthChallengeResponse of WirelessCharger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239700137References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20598

    Last Modified: 18 Apr 2025

    In sec_media_protect of media.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege of secure mode MFC Core with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242357514References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-20599

    Last Modified: 18 Apr 2025

    In Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242332706References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-20600

    Last Modified: 18 Apr 2025

    In TBD of TBD, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239847859References: N/A

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-20601

    Last Modified: 18 Apr 2025

    Product: AndroidVersions: Android kernelAndroid ID: A-204541506References: N/A

    Published: 16 Dec 2022
    4.9
    Medium

    CVE-2022-20606

    Last Modified: 18 Apr 2025

    In SAEMM_MiningCodecTableWithMsgIE of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-233230674References: N/A

    Published: 16 Dec 2022
    8.8
    High

    CVE-2022-20607

    Last Modified: 18 Apr 2025

    In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238914868References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-20608

    Last Modified: 18 Apr 2025

    In Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239239246References: N/A

    Published: 16 Dec 2022
    8.8
    High

    CVE-2022-20610

    Last Modified: 18 Apr 2025

    In cellular modem firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-240462530References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42513

    Last Modified: 18 Apr 2025

    In ProtocolEmbmsBuilder::BuildSetSession of protocolembmsbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241763204References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42514

    Last Modified: 17 Apr 2025

    In ProtocolImsBuilder::BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241763298References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42515

    Last Modified: 17 Apr 2025

    In MiscService::DoOemSetRtpPktlossThreshold of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241763503References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42516

    Last Modified: 17 Apr 2025

    In ProtocolSimBuilderLegacy::BuildSimGetGbaAuth of protocolsimbuilderlegacy.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241763577References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42517

    Last Modified: 17 Apr 2025

    In MiscService::DoOemSetTcsFci of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241763682References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42518

    Last Modified: 17 Apr 2025

    In BroadcastSmsConfigsRequestData::encode of smsdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242536278References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42520

    Last Modified: 17 Apr 2025

    In ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242994270References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42521

    Last Modified: 17 Apr 2025

    In encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243130019References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42522

    Last Modified: 17 Apr 2025

    In DoSetCarrierConfig of miscservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243130038References: N/A

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-42524

    Last Modified: 17 Apr 2025

    In sms_GetTpUdlIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243401445References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42525

    Last Modified: 17 Apr 2025

    In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243509750References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42526

    Last Modified: 17 Apr 2025

    In ConvertUtf8ToUcs2 of radio_hal_utils.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243509880References: N/A

    Published: 16 Dec 2022
    7.5
    High

    CVE-2022-42527

    Last Modified: 17 Apr 2025

    In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244448906References: N/A

    Published: 16 Dec 2022
    9.8
    Critical

    CVE-2022-42529

    Last Modified: 17 Apr 2025

    Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42530

    Last Modified: 17 Apr 2025

    In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242331893References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-42531

    Last Modified: 17 Apr 2025

    In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-231500967References: N/A

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42532

    Last Modified: 17 Apr 2025

    In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242332610References: N/A

    Published: 16 Dec 2022
    7.8
    High

    CVE-2022-42534

    Last Modified: 17 Apr 2025

    In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible privilege escalation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-237838301References: N/A

    Published: 16 Dec 2022
    5.5
    Medium

    CVE-2022-42535

    Last Modified: 17 Apr 2025

    In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770183

    Published: 16 Dec 2022
    5.3
    Medium

    CVE-2022-25626

    Last Modified: 18 Apr 2025

    An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42542

    Last Modified: 17 Apr 2025

    In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231445184

    Published: 16 Dec 2022
    4.4
    Medium

    CVE-2022-42543

    Last Modified: 17 Apr 2025

    In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-249998113References: N/A

    Published: 16 Dec 2022
    6
    Medium

    CVE-2022-26579

    Last Modified: 21 Nov 2024

    PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages. The attacker must have shell access to the device and gain root privileges in order to exploit this vulnerability.

    Published: 16 Dec 2022
    6.8
    Medium

    CVE-2022-26580

    Last Modified: 21 Nov 2024

    PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability.

    Published: 16 Dec 2022
    7.2
    High

    CVE-2022-31707

    Last Modified: 18 Apr 2025

    vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

    Published: 16 Dec 2022
    4.9
    Medium

    CVE-2022-31708

    Last Modified: 18 Apr 2025

    vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

    Published: 16 Dec 2022
    6.1
    Medium

    CVE-2022-36223

    Last Modified: 18 Apr 2025

    In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.

    Published: 16 Dec 2022
    9.8
    Critical

    CVE-2022-37832

    Last Modified: 18 Apr 2025

    Mutiny 7.2.0-10788 suffers from Hardcoded root password.

    Published: 16 Dec 2022
    4.3
    Medium

    CVE-2022-38756

    Last Modified: 18 Apr 2025

    A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42501

    Last Modified: 18 Apr 2025

    In HexString2Value of util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241231403References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42502

    Last Modified: 18 Apr 2025

    In FacilityLock::Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241231970References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42504

    Last Modified: 18 Apr 2025

    In CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241232209References: N/A

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42507

    Last Modified: 17 Apr 2025

    In ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241388774References: N/A

    Published: 16 Dec 2022
    7.5
    High

    CVE-2021-35252

    Last Modified: 17 Apr 2025

    Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42509

    Last Modified: 18 Apr 2025

    In CallDialReqData::encode of callreqdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241544307References: N/A

    Published: 16 Dec 2022
    4.5
    Medium

    CVE-2022-4130

    Last Modified: 14 Apr 2025

    A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.

    Published: 16 Dec 2022
    6.7
    Medium

    CVE-2022-42510

    Last Modified: 18 Apr 2025

    In StringsRequestData::encode of requestdata.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241762656References: N/A

    Published: 16 Dec 2022