Search CVE reports


Toggle filters

31 – 40 of 614 results


CVE-2022-20499

Medium priority
Ignored

In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed...

1 affected package

android-platform-frameworks-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-frameworks-base Ignored Ignored Ignored Ignored
Show less packages

CVE-2022-3168

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

1 affected package

android-platform-tools

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-tools Not affected Not in release Not in release
Show less packages

CVE-2023-0136

Medium priority

Some fixes available 1 of 2

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to execute incorrect security UI via a crafted HTML page. (Chromium security severity: Medium)

2 affected packages

android, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release
chromium-browser Not affected Not affected Not in release Fixed
Show less packages

CVE-2023-0133

Medium priority

Some fixes available 1 of 2

Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)

2 affected packages

android, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release
chromium-browser Not affected Not affected Not in release Fixed
Show less packages

CVE-2023-0130

Medium priority

Some fixes available 1 of 2

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

2 affected packages

chromium-browser, android

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not in release Fixed
android Not in release Not in release Not in release
Show less packages

CVE-2022-20502

Medium priority
Ignored

In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...

2 affected packages

android-platform-art, android-platform-tools

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-art Ignored Ignored Ignored Ignored
android-platform-tools Ignored Ignored Not in release Not in release
Show less packages

CVE-2022-20495

Medium priority
Ignored

In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional...

1 affected package

android-platform-frameworks-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-frameworks-base Ignored Ignored Ignored Ignored
Show less packages

CVE-2022-20491

Medium priority
Ignored

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges...

1 affected package

android-platform-frameworks-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-frameworks-base Ignored Ignored Ignored Ignored
Show less packages

CVE-2022-20488

Medium priority
Ignored

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges...

1 affected package

android-platform-frameworks-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-frameworks-base Ignored Ignored Ignored Ignored
Show less packages

CVE-2022-20487

Medium priority
Ignored

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges...

1 affected package

android-platform-frameworks-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android-platform-frameworks-base Ignored Ignored Ignored Ignored
Show less packages