CVE-2022-20204
Last Modified: 21 Nov 2024In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-171495100
CVE-2022-20202
Last Modified: 21 Nov 2024In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204704614
CVE-2022-20201
Last Modified: 21 Nov 2024In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220733817
CVE-2022-20200
Last Modified: 21 Nov 2024In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212695058
CVE-2022-20198
Last Modified: 21 Nov 2024In llcp_dlc_proc_connect_pdu of llcp_dlc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC stack with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-221851879
CVE-2022-20197
Last Modified: 21 Nov 2024In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-208279300
CVE-2022-20196
Last Modified: 21 Nov 2024In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535148
CVE-2022-20195
Last Modified: 21 Nov 2024In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-213172664
CVE-2022-20194
Last Modified: 21 Nov 2024In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-222684510
CVE-2022-20193
Last Modified: 21 Nov 2024In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212434116
CVE-2022-20192
Last Modified: 21 Nov 2024In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedded hierarchy due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-215912712
CVE-2022-20191
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A
CVE-2022-20190
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A
CVE-2022-20188
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A
CVE-2022-20185
Last Modified: 21 Nov 2024In TBD of TBD, there is a possible use after free bug. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208842348References: N/A
CVE-2022-20184
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A
CVE-2022-20183
Last Modified: 21 Nov 2024In hypx_create_blob_dmabuf of faceauth_hypx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-188911154References: N/A
CVE-2022-20182
Last Modified: 21 Nov 2024In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222348453References: N/A
CVE-2022-20181
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A
CVE-2022-20179
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-211683760References: N/A
CVE-2022-20178
Last Modified: 21 Nov 2024In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-224932775References: N/A
CVE-2022-20177
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A
CVE-2022-20176
Last Modified: 21 Nov 2024In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197787879References: N/A
CVE-2022-20175
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A
CVE-2022-20174
Last Modified: 21 Nov 2024In exynos_secEnv_init of mach-gs101.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210847407References: N/A
CVE-2022-20173
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
CVE-2022-20172
Last Modified: 21 Nov 2024In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-206987222References: N/A
CVE-2022-20171
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A
CVE-2022-20170
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A
CVE-2022-20169
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A
CVE-2022-20168
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-210594998References: N/A
CVE-2022-20167
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A
CVE-2022-20166
Last Modified: 21 Nov 2024In various methods of kernel base drivers, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-182388481References: Upstream kernel
CVE-2022-20165
Last Modified: 21 Nov 2024In asn1_parse of asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220868345References: N/A
CVE-2022-20164
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A
CVE-2022-20162
Last Modified: 21 Nov 2024In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223492713References: N/A
CVE-2022-20160
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A
CVE-2022-20159
Last Modified: 21 Nov 2024In asn1_ec_pkey_parse of acropora/crypto/asn1_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210971465References: N/A
CVE-2022-20156
Last Modified: 21 Nov 2024In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212803946References: N/A
CVE-2022-20155
Last Modified: 21 Nov 2024In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-176754369References: N/A
CVE-2022-20152
Last Modified: 21 Nov 2024In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006198References: N/A
CVE-2022-20151
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A
CVE-2022-20149
Last Modified: 21 Nov 2024Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A
CVE-2022-20148
Last Modified: 21 Nov 2024In TBD of TBD, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-219513976References: Upstream kernel
CVE-2022-20146
Last Modified: 21 Nov 2024In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This could lead to local information disclosure of private files with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-211757677References: N/A
CVE-2021-39806
Last Modified: 21 Nov 2024In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-215387420
CVE-2022-29406
Last Modified: 20 Feb 2025Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWebLab's WordPress Team Manager plugin <= 1.6.9 at WordPress.
CVE-2022-27859
Last Modified: 20 Feb 2025Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin <= 2.0 at WordPress.
CVE-2022-2087
Last Modified: 15 Apr 2025A vulnerability, which was classified as problematic, was found in SourceCodester Bank Management System 1.0. This affects the file /mnotice.php?id=2. The manipulation of the argument notice with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-2086
Last Modified: 15 Apr 2025A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 union select 1,sleep(10),3,4,5 --+ leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
