CVE-2022-20398
Last Modified: 21 Nov 2024In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-221859734
CVE-2022-20396
Last Modified: 21 Nov 2024In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-234440688
CVE-2022-20395
Last Modified: 21 Nov 2024In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-221855295
CVE-2022-20393
Last Modified: 21 Nov 2024In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-233735886
CVE-2022-20392
Last Modified: 5 Jun 2025In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213323615
CVE-2022-20391
Last Modified: 21 Nov 2024Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
CVE-2022-20390
Last Modified: 21 Nov 2024Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
CVE-2022-20389
Last Modified: 5 Jun 2025Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
CVE-2022-20388
Last Modified: 5 Jun 2025Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
CVE-2022-20387
Last Modified: 21 Nov 2024Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
CVE-2022-20386
Last Modified: 21 Nov 2024Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
CVE-2022-20385
Last Modified: 21 Nov 2024a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819
CVE-2021-0943
Last Modified: 21 Nov 2024In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-238916921
CVE-2021-0942
Last Modified: 21 Nov 2024The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read. However, given that the OOB read value is ending up as the address field of a struct I think i seems plausible that this could lead to an OOB write if the attacker is able to cause the OOB read to pull an interesting kernel address. Regardless if this is a read or write, it is a High severity issue in the kernel.Product: AndroidVersions: Android SoCAndroid ID: A-238904312
CVE-2021-0871
Last Modified: 21 Nov 2024In PVRSRVBridgePMRPDumpSymbolicAddr of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-238921253
CVE-2021-0697
Last Modified: 21 Nov 2024In PVRSRVRGXSubmitTransferKM of rgxtransfer.c, there is a possible user after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-238918403
CVE-2022-39206
Last Modified: 22 Apr 2025Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to control the Docker daemon on the host machine. This is a known dangerous pattern, as it can be used to break out of Docker containers and, in most cases, gain root privileges on the host system. This issue allows regular (non-admin) users to potentially take over the build infrastructure of a OneDev instance. Attackers need to have an account (or be able to register one) and need permission to create a project. Since code.onedev.io has the right preconditions for this to be exploited by remote attackers, it could have been used to hijack builds of OneDev itself, e.g. by injecting malware into the docker images that are built and pushed to Docker Hub. The impact is increased by this as described before. Users are advised to upgrade to 7.3.0 or higher. There are no known workarounds for this issue.
CVE-2022-39207
Last Modified: 22 Apr 2025Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact files are served by the webserver in the same context as the UI without any further restrictions. This leads to Cross-Site Scripting (XSS) when a user creates a build artifact that contains HTML. When accessing the artifact, the content is rendered by the browser, including any JavaScript that it contains. Since all cookies (except for the rememberMe one) do not set the HttpOnly flag, an attacker could steal the session of a victim and use it to impersonate them. To exploit this issue, attackers need to be able to modify the content of artifacts, which usually means they need to be able to modify a project's build spec. The exploitation requires the victim to click on an attacker's link. It can be used to elevate privileges by targeting admins of a OneDev instance. In the worst case, this can lead to arbitrary code execution on the server, because admins can create Server Shell Executors and use them to run any command on the server. This issue has been patched in version 7.3.0. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-39208
Last Modified: 22 Apr 2025Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repos and build artifacts. This file disclosure vulnerability can be used by unauthenticated attackers to leak all project files of any project. Since project IDs are incremental, an attacker could iterate through them and leak all project data. This issue has been resolved in version 7.3.0 and users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-38020
Last Modified: 11 Mar 2025Visual Studio Code Elevation of Privilege Vulnerability
CVE-2022-38019
Last Modified: 11 Mar 2025AV1 Video Extension Remote Code Execution Vulnerability
CVE-2022-38012
Last Modified: 11 Mar 2025Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2022-38010
Last Modified: 11 Mar 2025Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-38011
Last Modified: 11 Mar 2025Raw Image Extension Remote Code Execution Vulnerability
CVE-2022-38009
Last Modified: 11 Mar 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-38008
Last Modified: 11 Mar 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-38007
Last Modified: 11 Mar 2025Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
CVE-2022-38006
Last Modified: 11 Mar 2025Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-38005
Last Modified: 11 Mar 2025Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-38004
Last Modified: 11 Mar 2025Windows Fax Service Remote Code Execution Vulnerability
CVE-2022-37969
Last Modified: 13 Jan 2026Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-37963
Last Modified: 11 Mar 2025Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-37964
Last Modified: 11 Mar 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37962
Last Modified: 11 Mar 2025Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2022-37961
Last Modified: 11 Mar 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-37959
Last Modified: 11 Mar 2025Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability
CVE-2022-37958
Last Modified: 11 Mar 2025SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
CVE-2022-37957
Last Modified: 11 Mar 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37955
Last Modified: 11 Mar 2025Windows Group Policy Elevation of Privilege Vulnerability
CVE-2022-37954
Last Modified: 11 Mar 2025DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2022-35841
Last Modified: 11 Mar 2025Windows Enterprise App Management Service Remote Code Execution Vulnerability
CVE-2022-35838
Last Modified: 11 Mar 2025HTTP V3 Denial of Service Vulnerability
CVE-2022-35840
Last Modified: 11 Mar 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35836
Last Modified: 11 Mar 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35835
Last Modified: 11 Mar 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35834
Last Modified: 11 Mar 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35833
Last Modified: 11 Mar 2025Windows Secure Channel Denial of Service Vulnerability
CVE-2022-35832
Last Modified: 11 Mar 2025Windows Event Tracing Denial of Service Vulnerability
CVE-2022-35831
Last Modified: 11 Mar 2025Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2022-35828
Last Modified: 11 Mar 2025Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
