Vulnerabilities > Google > Low

DATE CVE VULNERABILITY TITLE RISK
2022-12-16 CVE-2022-20519 Missing Authorization vulnerability in Google Android 13.0
In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check.
local
low complexity
google CWE-862
3.3
2022-12-13 CVE-2022-20240 Missing Authorization vulnerability in Google Android 12.0
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check.
local
low complexity
google CWE-862
2.3
2022-12-08 CVE-2022-39914 Incorrect Authorization vulnerability in Google Android
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.
local
low complexity
google CWE-863
3.3
2022-12-08 CVE-2022-39913 Incorrect Authorization vulnerability in Google Android
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.
local
low complexity
google CWE-863
3.3
2022-12-08 CVE-2022-39912 Improper Handling of Exceptional Conditions vulnerability in Google Android
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
local
low complexity
google CWE-755
3.3
2022-12-08 CVE-2022-39906 Unspecified vulnerability in Google Android
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.
local
low complexity
google
3.3
2022-12-08 CVE-2022-39904 Information Exposure vulnerability in Google Android 10.0/11.0/12.0
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.
local
low complexity
google CWE-200
3.3
2022-12-08 CVE-2022-39903 Incorrect Authorization vulnerability in Google Android
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
local
low complexity
google CWE-863
3.3
2022-12-08 CVE-2022-39898 Unspecified vulnerability in Google Android
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
local
low complexity
google
3.3
2022-12-08 CVE-2022-39896 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
local
low complexity
google
3.3