CVE-2022-20000 to CVE-2022-20999
43 CVEs with public proof-of-concept exploits.
- CVE-2022-200041 PoCIn checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could…
- CVE-2022-200051 PoCIn validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK .…
- CVE-2022-200072 PoCsIn startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's…
- CVE-2022-200091 PoCIn various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead…
- CVE-2022-201261 PoCIn setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a…
- CVE-2022-201301 PoCIn transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead…
- CVE-2022-201382 PoCsIn ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send…
- CVE-2022-201401 PoCIn read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote…
- CVE-2022-201422 PoCsIn createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This…
- CVE-2022-201862 PoCsIn kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could…
- CVE-2022-202232 PoCsIn assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due…
- CVE-2022-202241 PoCIn AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote…
- CVE-2022-202291 PoCIn bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This…
- CVE-2022-203382 PoCsIn HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This…
- CVE-2022-203601 PoCIn setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege…
- CVE-2022-204092 PoCsIn io_identity_cow of io_uring.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation…
- CVE-2022-204131 PoCIn start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to…
- CVE-2022-204212 PoCsIn binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local…
- CVE-2022-204521 PoCIn initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could…
- CVE-2022-204701 PoCIn bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input…
- CVE-2022-204731 PoCIn toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to…
- CVE-2022-204741 PoCIn readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This…
- CVE-2022-204931 PoCIn Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to…
- CVE-2022-204941 PoCIn AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local…
- CVE-2022-206071 PoCIn the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code…
- CVE-2022-206171 PoCJenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution…
- CVE-2022-206601 PoCCisco IP Phones Information Disclosure Vulnerability
- CVE-2022-206994 PoCsKEVCisco Small Business RV Series Routers Vulnerabilities
- CVE-2022-207051 PoCCisco Small Business RV Series Routers Vulnerabilities
- CVE-2022-207071 PoCCisco Small Business RV Series Routers Vulnerabilities
- CVE-2022-207131 PoCA vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat…
- CVE-2022-207181 PoCCisco IOx Application Hosting Environment Vulnerabilities
- CVE-2022-207191 PoCCisco IOx Application Hosting Environment Vulnerabilities
- CVE-2022-207591 PoCCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
- CVE-2022-207751 PoCKEVCisco SD-WAN Software Privilege Escalation Vulnerability
- CVE-2022-207771 PoCCisco Enterprise NFV Infrastructure Software Vulnerabilities
- CVE-2022-207791 PoCCisco Enterprise NFV Infrastructure Software Vulnerabilities
- CVE-2022-207801 PoCCisco Enterprise NFV Infrastructure Software Vulnerabilities
- CVE-2022-208181 PoCCisco SD-WAN Software Privilege Escalation Vulnerabilities
- CVE-2022-208283 PoCsCisco FirePOWER Software for ASA FirePOWER Module Command Injection Vulnerability
- CVE-2022-208291 PoCCisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
- CVE-2022-208551 PoCCisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points Privilege Escalation Vulnerability
- CVE-2022-208661 PoCCisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability