VendorsGoogleandroid10.0
Vulnerabilities

Google Android 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1849CVEs
CVE-2022-47362
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47337
In media service, there is a missing permission check. This could lead to local denial of service in media service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47336
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47335
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-44428
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44429
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2022-44430
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-01-04 · Modified
5.5EPSS 0.001
CVE-2023-42647
In Ifaa service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2022-48391
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.5EPSS 0.001
CVE-2023-42653
In faceid service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-30936
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2022-48446
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.5EPSS 0.001
CVE-2022-48447
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.5EPSS 0.001
CVE-2022-47355
In log service, there is a missing permission check. This could lead to local denial of service in log service.
Published 2023-02-06 · Modified
5.5EPSS 0.001
CVE-2022-48460
In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local denial of service with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2022-47356
In log service, there is a missing permission check. This could lead to local denial of service in log service.
Published 2023-02-06 · Modified
5.5EPSS 0.001
CVE-2022-48448
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.5EPSS 0.001
CVE-2022-47354
In log service, there is a missing permission check. This could lead to local denial of service in log service.
Published 2023-02-06 · Modified
5.5EPSS 0.001
CVE-2023-42646
In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2022-36848
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
Published 2022-09-09 · Modified
5.5EPSS 0.001
CVE-2023-40639
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
Published 2023-10-08 · Modified
5.5EPSS 0.001
CVE-2023-40637
In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
Published 2023-10-08 · Modified
5.5EPSS 0.001
CVE-2023-40640
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
Published 2023-10-08 · Modified
5.5EPSS 0.001
CVE-2022-20219
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224585613
Published 2022-07-13 · Modified
5.5EPSS 0.001
CVE-2023-21260
In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
Published 2023-07-13 · Modified
5.5EPSS 0.001
CVE-2022-44420
In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2020-0119
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150500247
Published 2020-06-10 · Modified
5.4EPSS 0.007
CVE-2022-23433
Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.
Published 2022-02-11 · Modified
5.3EPSS 0.006
CVE-2020-26603
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows directory traversal for an unprivileged process to read arbitrary files. The Samsung ID is SVE-2020-18433 (October 2020).
Published 2020-10-06 · Modified
5.3EPSS 0.005
CVE-2019-9323
In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-30770233
Published 2019-09-27 · Modified
5.3EPSS 0.005
CVE-2020-11607
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Notification exposure occurs in Lockdown mode because of the Edge Lighting application. The Samsung ID is SVE-2020-16680 (April 2020).
Published 2020-04-08 · Modified
5.3EPSS 0.004
CVE-2019-20532
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is SVE-2019-15800 (December 2019).
Published 2020-03-24 · Modified
5.3EPSS 0.004
CVE-2020-15581
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature allows attackers to discover virtual addresses via vectors involving shared memory. The Samsung ID is SVE-2020-17605 (July 2020).
Published 2020-07-07 · Modified
5.3EPSS 0.003
CVE-2020-35552
An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chipsets) software. Attackers can obtain sensitive location information because the configuration file is incorrect. The Samsung ID is SVE-2020-18678 (December 2020).
Published 2020-12-18 · Modified
5.3EPSS 0.003
CVE-2020-12748
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and designate a different preferred SIM card. The Samsung ID is SVE-2020-16594 (May 2020).
Published 2020-05-11 · Modified
5.3EPSS 0.003
CVE-2020-26599
An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentication. The Samsung ID is SVE-2020-17079 (October 2020).
Published 2020-10-06 · Modified
5.3EPSS 0.003
CVE-2021-1037
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without requesting BLUETOOTH permissions.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-162951906
Published 2022-01-14 · Modified
5.3EPSS 0.003
CVE-2022-30716
Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.
Published 2022-06-07 · Modified
5.3EPSS 0.002
CVE-2022-30709
Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
Published 2022-06-07 · Modified
5.3EPSS 0.002
CVE-2022-30719
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
Published 2022-06-07 · Modified
5.3EPSS 0.002
← Prev40 / 47Next →