VendorsGoogleandroid10.0
Vulnerabilities

Google Android 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1849CVEs
CVE-2022-47323
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-20013
In vow driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05837742.
Published 2022-01-04 · Modified
6.4EPSS 0.001
CVE-2023-20623
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue ID: ALPS07559778.
Published 2023-03-07 · Modified
6.4EPSS 0.001
CVE-2023-45866
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Published 2023-12-08 · Modified
6.3EPSS 0.079
CVE-2022-47451
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.3EPSS 0.002
CVE-2022-23998
Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.
Published 2022-02-11 · Modified
6.2EPSS 0.006
CVE-2021-25344
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.
Published 2021-03-04 · Modified
6.2EPSS 0.001
CVE-2022-20350
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437
Published 2022-08-09 · Modified
6.2EPSS 0.001
CVE-2022-33689
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
Published 2022-07-11 · Modified
6.2EPSS 0.001
CVE-2022-33714
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
Published 2022-08-05 · Modified
6.2EPSS 0.001
CVE-2022-33702
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
Published 2022-07-11 · Modified
6.2EPSS 0.001
CVE-2022-33718
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
Published 2022-08-05 · Modified
6.2EPSS 0.001
CVE-2022-25822
An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.
Published 2022-03-08 · Modified
6.2EPSS 0.001
CVE-2022-30727
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
Published 2022-06-07 · Modified
6.2EPSS 0.001
CVE-2022-48442
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
6.2EPSS 0.001
CVE-2022-48440
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
6.2EPSS 0.001
CVE-2022-48441
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
6.2EPSS 0.001
CVE-2022-33691
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.
Published 2022-07-11 · Modified
6.2EPSS 0.001
CVE-2022-33723
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
Published 2022-08-05 · Modified
6.1EPSS 0.001
CVE-2022-33727
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
Published 2022-08-05 · Modified
6.1EPSS 0.001
CVE-2022-22268
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
Published 2022-01-07 · Modified
6.1EPSS 0.001
CVE-2021-25382
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
Published 2021-04-23 · Modified
6.1EPSS 0.001
CVE-2021-25490
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
Published 2021-10-06 · Modified
6.0EPSS 0.008
CVE-2022-23426
A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.
Published 2022-02-11 · Modified
6.0EPSS 0.001
CVE-2019-9414
In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111893041
Published 2019-09-27 · Modified
5.9EPSS 0.006
CVE-2022-20081
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID: ALPS06461919.
Published 2022-04-11 · Modified
5.9EPSS 0.006
CVE-2019-9399
The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115635664
Published 2019-09-27 · Modified
5.9EPSS 0.004
CVE-2021-25457
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
Published 2021-09-09 · Modified
5.9EPSS 0.001
CVE-2022-33729
Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.
Published 2022-08-05 · Modified
5.9EPSS 0.001
CVE-2022-36861
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.
Published 2022-09-09 · Modified
5.9EPSS 0.001
CVE-2022-48445
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.9EPSS 0.001
CVE-2022-48443
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.9EPSS 0.001
CVE-2022-48444
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.9EPSS 0.001
CVE-2022-39885
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
Published 2022-11-09 · Modified
5.9EPSS 0.001
CVE-2022-39886
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
Published 2022-11-09 · Modified
5.9EPSS 0.001
CVE-2020-0379
In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150156492
Published 2020-09-17 · Modified
5.7EPSS 0.003
CVE-2022-39899
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
Published 2022-12-08 · Modified
5.7EPSS 0.001
CVE-2021-25501
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
Published 2021-11-05 · Modified
5.7EPSS 0.001
CVE-2022-47369
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
5.7EPSS 0.001
CVE-2022-47368
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
5.7EPSS 0.001
← Prev28 / 47Next →