Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 7761 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-20383 1 Google 1 Android 2022-08-13 N/A 7.8 HIGH
In AllocateInternalBuffers of g3aa_buffer_allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222408847References: N/A
CVE-2022-20384 1 Google 1 Android 2022-08-13 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
CVE-2022-20400 1 Google 1 Android 2022-08-13 N/A 9.8 CRITICAL
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-225178325References: N/A
CVE-2022-20407 1 Google 1 Android 2022-08-13 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A
CVE-2022-20406 1 Google 1 Android 2022-08-13 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A
CVE-2022-20401 1 Google 1 Android 2022-08-13 N/A 7.5 HIGH
In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post-authentication with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-226446030References: N/A
CVE-2022-20402 1 Google 1 Android 2022-08-13 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
CVE-2022-20403 1 Google 1 Android 2022-08-13 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
CVE-2022-20404 1 Google 1 Android 2022-08-13 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A
CVE-2022-20405 1 Google 1 Android 2022-08-13 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
CVE-2021-39696 1 Google 1 Android 2022-08-12 N/A 7.8 HIGH
In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-185810717
CVE-2022-33727 1 Google 1 Android 2022-08-12 N/A 6.1 MEDIUM
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
CVE-2021-25349 2 Google, Samsung 2 Android, Slow Motion Editor 2022-08-12 4.6 MEDIUM 7.8 HIGH
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
CVE-2021-25373 2 Google, Samsung 2 Android, Customization Service 2022-08-12 4.6 MEDIUM 7.8 HIGH
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2022-33723 1 Google 1 Android 2022-08-12 N/A 6.1 MEDIUM
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
CVE-2022-33732 1 Google 1 Android 2022-08-12 N/A 7.1 HIGH
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.
CVE-2022-20344 1 Google 1 Android 2022-08-12 N/A 7.0 HIGH
In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-232541124
CVE-2022-20345 1 Google 1 Android 2022-08-12 N/A 8.8 HIGH
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481
CVE-2022-20346 1 Google 1 Android 2022-08-12 N/A 6.5 MEDIUM
In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-230493653
CVE-2022-20347 1 Google 1 Android 2022-08-12 N/A 8.8 HIGH
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228450811