Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-11-11 CVE-2022-33973 Unspecified vulnerability in Intel Wlan Authentication and Privacy Infrastructure
Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel
3.3
2022-11-10 CVE-2022-39388 Incorrect Authorization vulnerability in Istio 1.15.0/1.15.1/1.15.2
Istio is an open platform to connect, manage, and secure microservices.
low complexity
istio CWE-863
3.5
2022-11-09 CVE-2022-39879 Unspecified vulnerability in Google Android 11.0/12.0
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
local
low complexity
google
3.3
2022-11-09 CVE-2022-39884 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
local
low complexity
google
3.3
2022-11-09 CVE-2022-39885 Improper Handling of Exceptional Conditions vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
local
low complexity
google CWE-755
3.3
2022-11-09 CVE-2022-39886 Improper Handling of Exceptional Conditions vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
local
low complexity
google CWE-755
3.3
2022-11-09 CVE-2022-39887 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
local
low complexity
google
3.3
2022-11-09 CVE-2022-39889 Unspecified vulnerability in Samsung Galaxywatch4Plugin 2.2.11.22102751
Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.
local
low complexity
samsung
3.3
2022-11-09 CVE-2022-39893 Information Exposure Through Log Files vulnerability in Samsung Galaxy Buds PRO Manage
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.
local
low complexity
samsung CWE-532
3.3
2022-11-08 CVE-2022-20446 Missing Authorization vulnerability in Google Android 10.0/11.0
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check.
local
low complexity
google CWE-862
3.3