2022 CVE Vulnerabilities

27,540 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20280LOW3.3In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lea...
CVE-2022-20279MEDIUM5.5In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due...
CVE-2022-20278MEDIUM5.5In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering....
CVE-2022-20277MEDIUM5.5In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due...
CVE-2022-20276MEDIUM5.5In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due...
CVE-2022-20275MEDIUM5.5In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due...
CVE-2022-20274HIGH7.8In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of scr...
CVE-2022-20273MEDIUM6.5In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote informatio...
CVE-2022-20272MEDIUM5.5In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to ...
CVE-2022-20271HIGH7.8In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or ins...
CVE-2022-20270MEDIUM5.5In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could le...
CVE-2022-20269MEDIUM6.8In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat...
CVE-2022-20268HIGH7.8In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a pe...
CVE-2022-20267LOW3.3In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing pe...
CVE-2022-20266MEDIUM5In Companion, there is a possible way to keep a service running with elevated importance without showing foreground serv...
CVE-2022-20265MEDIUM4.6In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass. This could lead to...
CVE-2022-20263MEDIUM5.5In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could l...
CVE-2022-20262LOW3.3In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. T...
CVE-2022-20261LOW2.3In LocationManager, there is a possible way to get location information due to a missing permission check. This could le...
CVE-2022-20260MEDIUM5.5In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial ...
CVE-2022-20259MEDIUM5.5In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local info...
CVE-2022-20258HIGH7.8In Bluetooth, there is a possible way to bypass compiler exploit mitigations due to a configuration error. This could le...
CVE-2022-20257LOW3.3In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the...
CVE-2022-20256MEDIUM6.4In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation o...
CVE-2022-20255MEDIUM4.4In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. T...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now