CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-20204

    Last Modified: 21 Nov 2024

    In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-171495100

    Published: 15 Jun 2022
    6.5
    Medium

    CVE-2022-20202

    Last Modified: 21 Nov 2024

    In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204704614

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-20201

    Last Modified: 21 Nov 2024

    In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220733817

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-20200

    Last Modified: 21 Nov 2024

    In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212695058

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20198

    Last Modified: 21 Nov 2024

    In llcp_dlc_proc_connect_pdu of llcp_dlc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC stack with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-221851879

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-20197

    Last Modified: 21 Nov 2024

    In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-208279300

    Published: 15 Jun 2022
    5
    Medium

    CVE-2022-20196

    Last Modified: 21 Nov 2024

    In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535148

    Published: 15 Jun 2022
    5
    Medium

    CVE-2022-20195

    Last Modified: 21 Nov 2024

    In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-213172664

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-20194

    Last Modified: 21 Nov 2024

    In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-222684510

    Published: 15 Jun 2022
    7.3
    High

    CVE-2022-20193

    Last Modified: 21 Nov 2024

    In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212434116

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-20192

    Last Modified: 21 Nov 2024

    In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedded hierarchy due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-215912712

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20191

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-209324757References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20190

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20188

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-20185

    Last Modified: 21 Nov 2024

    In TBD of TBD, there is a possible use after free bug. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208842348References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20184

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-20183

    Last Modified: 21 Nov 2024

    In hypx_create_blob_dmabuf of faceauth_hypx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-188911154References: N/A

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20182

    Last Modified: 21 Nov 2024

    In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222348453References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20181

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20179

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-211683760References: N/A

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-20178

    Last Modified: 21 Nov 2024

    In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-224932775References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20177

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20176

    Last Modified: 21 Nov 2024

    In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197787879References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20175

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20174

    Last Modified: 21 Nov 2024

    In exynos_secEnv_init of mach-gs101.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210847407References: N/A

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20173

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-20172

    Last Modified: 21 Nov 2024

    In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-206987222References: N/A

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20171

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20170

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20169

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20168

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-210594998References: N/A

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20167

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-20166

    Last Modified: 21 Nov 2024

    In various methods of kernel base drivers, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-182388481References: Upstream kernel

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20165

    Last Modified: 21 Nov 2024

    In asn1_parse of asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220868345References: N/A

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20164

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-204891956References: N/A

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20162

    Last Modified: 21 Nov 2024

    In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223492713References: N/A

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2022-20160

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-210083655References: N/A

    Published: 15 Jun 2022
    4.4
    Medium

    CVE-2022-20159

    Last Modified: 21 Nov 2024

    In asn1_ec_pkey_parse of acropora/crypto/asn1_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210971465References: N/A

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-20156

    Last Modified: 21 Nov 2024

    In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212803946References: N/A

    Published: 15 Jun 2022
    7
    High

    CVE-2022-20155

    Last Modified: 21 Nov 2024

    In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-176754369References: N/A

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-20152

    Last Modified: 21 Nov 2024

    In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006198References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20151

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-20149

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A

    Published: 15 Jun 2022
    6.4
    Medium

    CVE-2022-20148

    Last Modified: 21 Nov 2024

    In TBD of TBD, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-219513976References: Upstream kernel

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-20146

    Last Modified: 21 Nov 2024

    In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This could lead to local information disclosure of private files with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-211757677References: N/A

    Published: 15 Jun 2022
    7.8
    High

    CVE-2021-39806

    Last Modified: 21 Nov 2024

    In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-215387420

    Published: 15 Jun 2022
    4.1
    Medium

    CVE-2022-29406

    Last Modified: 20 Feb 2025

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWebLab's WordPress Team Manager plugin <= 1.6.9 at WordPress.

    Published: 15 Jun 2022
    4.1
    Medium

    CVE-2022-27859

    Last Modified: 20 Feb 2025

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin <= 2.0 at WordPress.

    Published: 15 Jun 2022
    3.5
    Low

    CVE-2022-2087

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in SourceCodester Bank Management System 1.0. This affects the file /mnotice.php?id=2. The manipulation of the argument notice with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jun 2022
    6.3
    Medium

    CVE-2022-2086

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 union select 1,sleep(10),3,4,5 --+ leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jun 2022