Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 6.4
CVE-2022-20154

In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with Syst…

Mitigation only
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20143

In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local de…

Mitigation only
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20146

In uploadFile of FileUploadServiceImpl.java, there is a possible incorrect file access due to a confused deputy. This could lead to local information…

Mitigation only
Fix from $1,600 2022-06-15
Android CRITICAL 9.8
CVE-2022-20127EPSS 7%

In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no add…

Mitigation only
Fix from $2,300 2022-06-15
Android CRITICAL 9.8
CVE-2022-20130EPSS 9%

In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote co…

Mitigation only
Fix from $2,300 2022-06-15
Android HIGH 7.8
CVE-2022-20124

In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications for other users due to a per…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20133

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead t…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20134

In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20135

In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User e…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.5
CVE-2022-20123

In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote i…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.5
CVE-2022-20131

In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informa…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2021-39691

In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalati…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2022-20126

In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permissio…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2022-20137

In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permissi…

Patch available
Fix from $1,950 2022-06-15
Android MEDIUM 6.8
CVE-2022-20125

In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if a…

Mitigation only
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20129

In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper inp…

Mitigation only
Fix from $1,600 2022-06-15
Kctf HIGH 7.5
CVE-2022-31055

kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was bro…

Fix: 1.6.0+
Fix from $1,950 2022-06-13
Android MEDIUM 5.5
CVE-2022-30727

Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 …

Mitigation only
Fix from $1,600 2022-06-07
Android CRITICAL 9.8
CVE-2022-30722

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Ac…

Mitigation only
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30711

Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30712

Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

No fix yet
Fix from $2,300 2022-06-07
Android CRITICAL 9.1
CVE-2022-30713

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07
Android HIGH 7.8
CVE-2022-30726

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to la…

Mitigation only
Fix from $1,950 2022-06-07
Android HIGH 7.5
CVE-2022-30717

Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

Mitigation only
Fix from $1,950 2022-06-07
Android MEDIUM 5.3
CVE-2022-30715

Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30716

Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast mess…

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30719

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30720

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android MEDIUM 5.3
CVE-2022-30721

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

Mitigation only
Fix from $1,600 2022-06-07
Android CRITICAL 9.1
CVE-2022-30710

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Mitigation only
Fix from $2,300 2022-06-07