Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 35453 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-20675 1 Cisco 4 Asyncos, Email Security Appliance, Secure Email And Web Manager and 1 more 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) condition. This vulnerability is due to an open port listener on TCP port 199. An attacker could exploit this vulnerability by connecting to TCP port 199. A successful exploit could allow the attacker to crash the SNMP service, resulting in a DoS condition.
CVE-2022-20625 1 Cisco 110 Firepower 4110, Firepower 4112, Firepower 4115 and 107 more 2024-11-21 6.1 MEDIUM 4.3 MEDIUM
A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisco Discovery Protocol service. An attacker could exploit this vulnerability by sending a series of malicious Cisco Discovery Protocol messages to an affected device. A successful exploit could allow the attacker to cause the Cisco Discovery Protocol service to fail and restart. In rare conditions, repeated failures of the process could occur, which could cause the entire device to restart.
CVE-2022-20599 1 Google 1 Android 2024-11-21 N/A 6.7 MEDIUM
In Pixel firmware, there is a possible exposure of sensitive memory due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242332706References: N/A
CVE-2022-20531 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2022-20440 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259918
CVE-2022-20439 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In Messaging, There has unauthorized provider, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242266172
CVE-2022-20438 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242259920
CVE-2022-20437 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242258929
CVE-2022-20420 1 Google 1 Android 2024-11-21 N/A 7.8 HIGH
In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way to bypass device policy restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238377411
CVE-2022-20419 1 Google 1 Android 2024-11-21 N/A 7.8 HIGH
In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-237290578
CVE-2022-20415 1 Google 1 Android 2024-11-21 N/A 7.8 HIGH
In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-231322873
CVE-2022-20413 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634
CVE-2022-20408 1 Google 1 Android 2024-11-21 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-204782372References: N/A
CVE-2022-20407 1 Google 1 Android 2024-11-21 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A
CVE-2022-20406 1 Google 1 Android 2024-11-21 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A
CVE-2022-20405 1 Google 1 Android 2024-11-21 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
CVE-2022-20404 1 Google 1 Android 2024-11-21 N/A 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A
CVE-2022-20403 1 Google 1 Android 2024-11-21 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
CVE-2022-20402 1 Google 1 Android 2024-11-21 N/A 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
CVE-2022-20391 1 Google 1 Android 2024-11-21 N/A 9.8 CRITICAL
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000