Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-08-11 CVE-2022-20252 Information Exposure Through Discrepancy vulnerability in Google Android 13.0.0
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2022-08-10 CVE-2022-20358 Missing Authorization vulnerability in Google Android
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check.
local
low complexity
google CWE-862
3.3
2022-08-10 CVE-2022-30629 Use of Insufficiently Random Values vulnerability in Golang GO
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
network
high complexity
golang CWE-330
3.1
2022-08-05 CVE-2022-2307 Incomplete Cleanup vulnerability in Gitlab
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.
network
low complexity
gitlab CWE-459
3.8
2022-08-05 CVE-2022-2456 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab
2.7
2022-08-05 CVE-2022-2459 Missing Authorization vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-862
2.7
2022-08-05 CVE-2022-33714 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
local
low complexity
google
3.3
2022-08-05 CVE-2022-33718 Unspecified vulnerability in Google Android 10.0/11.0/12.0
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
local
low complexity
google
3.3
2022-08-05 CVE-2022-33720 Improper Authentication vulnerability in Google Android 10.0/11.0
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
low complexity
google CWE-287
2.4
2022-08-05 CVE-2022-33722 Unspecified vulnerability in Google Android 12.0
Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.
local
low complexity
google
3.3