Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 575 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-20387 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
CVE-2021-39815 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232440670
CVE-2022-39862 2 Google, Samsung 2 Android, Dynamic Lockscreen 2023-12-10 N/A 9.8 CRITICAL
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.
CVE-2022-20385 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819
CVE-2022-20405 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
CVE-2022-20122 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339
CVE-2022-20389 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
CVE-2022-26447 3 Google, Mediatek, Yoctoproject 27 Android, Mt6580, Mt6735 and 24 more 2023-12-10 N/A 9.8 CRITICAL
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.
CVE-2022-20391 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
CVE-2022-20237 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-229621649References: N/A
CVE-2022-20378 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
CVE-2022-33719 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.
CVE-2022-20365 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
CVE-2022-20384 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
CVE-2022-20238 1 Google 1 Android 2023-12-10 10.0 HIGH 9.8 CRITICAL
'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions: Android SoCAndroid ID: A-233154555
CVE-2022-20403 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
CVE-2022-20229 1 Google 1 Android 2023-12-10 10.0 HIGH 9.8 CRITICAL
In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224536184
CVE-2022-20361 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832
CVE-2022-20381 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
CVE-2022-20400 1 Google 1 Android 2023-12-10 N/A 9.8 CRITICAL
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-225178325References: N/A