VendorsGoogleandroid10.0
Vulnerabilities

Google Android 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1849CVEs
CVE-2021-25365
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
Published 2021-04-09 · Modified
7.8EPSS 0.001
CVE-2021-25510
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.
Published 2021-12-08 · Modified
7.8EPSS 0.001
CVE-2022-48383
.In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Published 2023-05-09 · Modified
7.8EPSS 0.001
CVE-2022-39854
Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
Published 2022-10-07 · Modified
7.8EPSS 0.001
CVE-2021-0953
In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-184046278
Published 2021-12-15 · Modified
7.8EPSS 0.001
CVE-2021-39807
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-209446496
Published 2022-04-12 · Modified
7.8EPSS 0.001
CVE-2021-39808
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209966086
Published 2022-04-12 · Modified
7.8EPSS 0.001
CVE-2021-0486
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-171430330
Published 2021-07-14 · Modified
7.8EPSS 0.001
CVE-2022-27833
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
Published 2022-04-11 · Modified
7.8EPSS 0.001
CVE-2022-20392
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213323615
Published 2022-09-13 · Modified
7.8EPSS 0.001
CVE-2021-25412
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.
Published 2021-06-11 · Modified
7.8EPSS 0.001
CVE-2022-36842
A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36843
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-20451
In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235098883
Published 2022-11-08 · Modified
7.8EPSS 0.001
CVE-2022-36863
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-20415
In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-231322873
Published 2022-10-11 · Modified
7.8EPSS 0.001
CVE-2022-36862
A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36860
A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36855
A use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36858
A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36845
A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36844
A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36841
A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-36846
A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-30755
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.
Published 2022-07-11 · Modified
7.8EPSS 0.001
CVE-2022-20084
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498874; Issue ID: ALPS06498874.
Published 2022-05-03 · Modified
7.8EPSS 0.001
CVE-2022-20093
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498868; Issue ID: ALPS06498868.
Published 2022-05-03 · Modified
7.8EPSS 0.001
CVE-2021-25512
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.
Published 2021-12-08 · Modified
7.8EPSS 0.001
CVE-2021-25428
Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.
Published 2021-07-08 · Modified
7.8EPSS 0.001
CVE-2022-25815
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Published 2022-03-08 · Modified
7.8EPSS 0.001
CVE-2022-39119
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-33695
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.
Published 2022-07-11 · Modified
7.8EPSS 0.001
CVE-2023-42693
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42692
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42690
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42689
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42688
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42687
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42686
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42685
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
← Prev14 / 47Next →