CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-20317

    Last Modified: 21 Nov 2024

    In SystemUI, there is a possible way to unexpectedly enable the external speaker due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-190199063

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20316

    Last Modified: 21 Nov 2024

    In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-190726121

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20315

    Last Modified: 21 Nov 2024

    In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-191058227

    Published: 11 Aug 2022
    6.7
    Medium

    CVE-2022-20314

    Last Modified: 21 Nov 2024

    In KeyChain, there is a possible spoof keychain chooser activity request due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-191876118

    Published: 11 Aug 2022
    6.8
    Medium

    CVE-2022-20313

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-192206329

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20312

    Last Modified: 21 Nov 2024

    In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is not needed forexploitationProduct: AndroidVersions: Android-13Android ID: A-192244925

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20311

    Last Modified: 21 Nov 2024

    In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-192663553

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20310

    Last Modified: 21 Nov 2024

    In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-192663798

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20309

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194694094

    Published: 11 Aug 2022
    7.5
    High

    CVE-2022-20308

    Last Modified: 21 Nov 2024

    In hostapd, there is a possible insecure configuration due to an insecure default value. This could lead to remote denial of service of the wifi hotspot with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-197874458

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20307

    Last Modified: 21 Nov 2024

    In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-198782887

    Published: 11 Aug 2022
    6.7
    Medium

    CVE-2022-20306

    Last Modified: 21 Nov 2024

    In Camera Provider HAL, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199680794

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20305

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible disclosure of available account types due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199751623

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20304

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199751919

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20303

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200573021

    Published: 11 Aug 2022
    7.6
    High

    CVE-2022-20302

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200746457

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20301

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200956614

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20300

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200956588

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20299

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201415895

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20298

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201416182

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20297

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201561699

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20296

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201794303

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20295

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202160584

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20294

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to learn about an account present on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202160705

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20293

    Last Modified: 21 Nov 2024

    In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202298672

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20292

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202975040

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20291

    Last Modified: 21 Nov 2024

    In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-203430648

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20290

    Last Modified: 21 Nov 2024

    In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-203549963

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20289

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-203683960

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20288

    Last Modified: 21 Nov 2024

    In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204082360

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20287

    Last Modified: 21 Nov 2024

    In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204082784

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20286

    Last Modified: 21 Nov 2024

    In Connectivity, there is a possible bypass the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230866011

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20285

    Last Modified: 21 Nov 2024

    In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230868108

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20284

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone accounts with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231986341

    Published: 11 Aug 2022
    8.8
    High

    CVE-2022-20283

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233069336

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20282

    Last Modified: 21 Nov 2024

    In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204083104

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20281

    Last Modified: 21 Nov 2024

    In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204083967

    Published: 11 Aug 2022
    3.3
    Low

    CVE-2022-20280

    Last Modified: 21 Nov 2024

    In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204117261

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20279

    Last Modified: 21 Nov 2024

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204877302

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20278

    Last Modified: 21 Nov 2024

    In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205130113

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20277

    Last Modified: 21 Nov 2024

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205145497

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20276

    Last Modified: 21 Nov 2024

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205706731

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20275

    Last Modified: 21 Nov 2024

    In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205836975

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20274

    Last Modified: 21 Nov 2024

    In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-206470146

    Published: 11 Aug 2022
    6.5
    Medium

    CVE-2022-20273

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-206478022

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20272

    Last Modified: 21 Nov 2024

    In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-207672568

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20271

    Last Modified: 21 Nov 2024

    In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-207672635

    Published: 11 Aug 2022
    5.5
    Medium

    CVE-2022-20270

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-209005023

    Published: 11 Aug 2022
    6.8
    Medium

    CVE-2022-20269

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-209062898

    Published: 11 Aug 2022
    7.8
    High

    CVE-2022-20268

    Last Modified: 21 Nov 2024

    In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a permissions bypass. This could lead to local escalation of privilege on an enterprise managed device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-210468836

    Published: 11 Aug 2022