2022 CVE Vulnerabilities
27,540 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20280 | LOW | 3.3 | 0.1% | Aug 12, 2022 | In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lea... |
| CVE-2022-20279 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due... |
| CVE-2022-20278 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering.... |
| CVE-2022-20277 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due... |
| CVE-2022-20276 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due... |
| CVE-2022-20275 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due... |
| CVE-2022-20274 | HIGH | 7.8 | 0.1% | Aug 12, 2022 | In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of scr... |
| CVE-2022-20273 | MEDIUM | 6.5 | 0.2% | Aug 12, 2022 | In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote informatio... |
| CVE-2022-20272 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to ... |
| CVE-2022-20271 | HIGH | 7.8 | 0.1% | Aug 12, 2022 | In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or ins... |
| CVE-2022-20270 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could le... |
| CVE-2022-20269 | MEDIUM | 6.8 | 0.2% | Aug 12, 2022 | In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat... |
| CVE-2022-20268 | HIGH | 7.8 | 0.1% | Aug 12, 2022 | In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a pe... |
| CVE-2022-20267 | LOW | 3.3 | 0.1% | Aug 12, 2022 | In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing pe... |
| CVE-2022-20266 | MEDIUM | 5 | 0.1% | Aug 12, 2022 | In Companion, there is a possible way to keep a service running with elevated importance without showing foreground serv... |
| CVE-2022-20265 | MEDIUM | 4.6 | 0.1% | Aug 12, 2022 | In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass. This could lead to... |
| CVE-2022-20263 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could l... |
| CVE-2022-20262 | LOW | 3.3 | 0.1% | Aug 12, 2022 | In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. T... |
| CVE-2022-20261 | LOW | 2.3 | 0.1% | Aug 12, 2022 | In LocationManager, there is a possible way to get location information due to a missing permission check. This could le... |
| CVE-2022-20260 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial ... |
| CVE-2022-20259 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local info... |
| CVE-2022-20258 | HIGH | 7.8 | 0.1% | Aug 12, 2022 | In Bluetooth, there is a possible way to bypass compiler exploit mitigations due to a configuration error. This could le... |
| CVE-2022-20257 | LOW | 3.3 | 0.1% | Aug 12, 2022 | In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the... |
| CVE-2022-20256 | MEDIUM | 6.4 | 0.1% | Aug 12, 2022 | In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation o... |
| CVE-2022-20255 | MEDIUM | 4.4 | 0.1% | Aug 12, 2022 | In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. T... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now