Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2022-22270 Files or Directories Accessible to External Parties vulnerability in Google Android 10.0/11.0/9.0
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
local
low complexity
google CWE-552
3.3
2022-01-10 CVE-2022-22272 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
local
low complexity
google
3.3
2022-01-10 CVE-2022-22283 Insufficient Session Expiration vulnerability in Samsung Health 6.16/6.17/6.19.1.0001
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
local
low complexity
samsung CWE-613
3.3
2022-01-10 CVE-2021-38894 Information Exposure Through an Error Message vulnerability in IBM Security Verify Access 10.0.0/10.0.1.0/10.0.2.0
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
2.7
2022-01-07 CVE-2021-25743 Unspecified vulnerability in Kubernetes
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal.
network
high complexity
kubernetes
3.0
2022-01-05 CVE-2021-22567 Unspecified vulnerability in Dart Software Development KIT
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign.
network
low complexity
dart
3.5
2022-01-03 CVE-2021-45916 Improper Input Validation vulnerability in SMR Shenwang Endpoint Protection Security System
The programming function of Shockwall system has an improper input validation vulnerability.
low complexity
smr CWE-20
3.5
2021-12-25 CVE-2021-45486 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.
low complexity
linux oracle CWE-327
3.5
2021-12-23 CVE-2017-2375 Unspecified vulnerability in Apple Iphone OS
An issue existed in preventing the uploading of CallKit call history to iCloud.
local
low complexity
apple
3.3
2021-12-20 CVE-2021-43030 Unspecified vulnerability in Adobe Premiere Rush 1.5.12/1.5.16/1.5.8
Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose arbitrary data on affected installations.
local
low complexity
adobe
3.3