Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 8334 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24928 1 Google 1 Android 2022-03-16 7.2 HIGH 7.8 HIGH
Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.
CVE-2022-25814 1 Google 1 Android 2022-03-16 4.6 MEDIUM 7.8 HIGH
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2022-25815 1 Google 1 Android 2022-03-16 4.6 MEDIUM 7.8 HIGH
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2022-25816 1 Google 1 Android 2022-03-16 2.1 LOW 4.6 MEDIUM
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
CVE-2022-25818 1 Google 1 Android 2022-03-16 7.5 HIGH 9.8 CRITICAL
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
CVE-2022-25819 2 Google, Samsung 2 Android, Exynos 2022-03-16 2.1 LOW 5.5 MEDIUM
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.
CVE-2022-25821 2 Google, Samsung 2 Android, Exynos 2022-03-16 3.6 LOW 7.1 HIGH
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
CVE-2022-25820 1 Google 1 Android 2022-03-16 2.1 LOW 4.6 MEDIUM
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.
CVE-2022-25822 1 Google 1 Android 2022-03-16 4.9 MEDIUM 6.2 MEDIUM
An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.
CVE-2022-20047 2 Google, Mediatek 11 Android, Mt5816, Mt5835 and 8 more 2022-03-15 7.2 HIGH 7.8 HIGH
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917489; Issue ID: ALPS05917489.
CVE-2022-23729 1 Google 1 Android 2022-03-11 6.9 MEDIUM 7.8 HIGH
When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
CVE-2022-24925 1 Google 1 Android 2022-02-22 6.8 MEDIUM 6.5 MEDIUM
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.
CVE-2022-24001 1 Google 1 Android 2022-02-22 2.1 LOW 4.6 MEDIUM
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.
CVE-2022-24000 1 Google 1 Android 2022-02-22 2.1 LOW 3.3 LOW
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
CVE-2022-23999 1 Google 1 Android 2022-02-22 2.1 LOW 3.3 LOW
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
CVE-2022-23998 2 Google, Samsung 2 Android, Camera 2022-02-22 4.3 MEDIUM 5.5 MEDIUM
Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.
CVE-2022-0300 1 Google 2 Android, Chrome 2022-02-19 6.8 MEDIUM 8.8 HIGH
Use after free in Text Input Method Editor in Google Chrome on Android prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-23425 2 Google, Samsung 2 Android, Exynos 2022-02-18 7.5 HIGH 9.8 CRITICAL
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.
CVE-2022-22292 1 Google 1 Android 2022-02-18 4.6 MEDIUM 7.8 HIGH
Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.
CVE-2022-22291 1 Google 1 Android 2022-02-18 2.1 LOW 5.5 MEDIUM
Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.