VendorsGoogleandroid12.0
Vulnerabilities

Google Android 12.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1915CVEs
CVE-2022-39118
In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44425
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44426
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44427
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44431
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44432
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44440
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44441
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44442
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44443
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44444
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44445
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44446
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2021-0998
In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193442575
Published 2021-12-15 · Modified
5.5EPSS 0.001
CVE-2022-42782
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
Published 2022-12-06 · Modified
5.5EPSS 0.001
CVE-2021-39700
In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201645790
Published 2022-05-10 · Modified
5.5EPSS 0.001
CVE-2023-40075
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2022-42772
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
Published 2022-12-06 · Modified
5.5EPSS 0.001
CVE-2022-44422
In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44423
In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44424
In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44434
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44435
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44436
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44437
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44438
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44439
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2023-33882
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2022-20448
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-237540408
Published 2022-11-08 · Modified
5.5EPSS 0.001
CVE-2022-20046
In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410.
Published 2022-02-09 · Modified
5.5EPSS 0.001
CVE-2023-21283
In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.001
CVE-2021-39778
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-196406138
Published 2022-03-30 · Modified
5.5EPSS 0.001
CVE-2023-35675
In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
5.5EPSS 0.001
CVE-2022-20092
In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366061; Issue ID: ALPS06366061.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2022-20104
In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06284104.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2021-1005
In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186530889
Published 2021-12-15 · Modified
5.5EPSS 0.001
CVE-2021-1009
In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189858128
Published 2021-12-15 · Modified
5.5EPSS 0.001
CVE-2021-39773
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-191276656
Published 2022-03-30 · Modified
5.5EPSS 0.001
CVE-2021-39775
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-206465854
Published 2022-03-30 · Modified
5.5EPSS 0.001
CVE-2021-1012
In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195412179
Published 2021-12-15 · Modified
5.5EPSS 0.001
← Prev31 / 48Next →