CVE-2022-20483
published 2022-12-13CVE-2022-20483: In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.61%
45.1th percentile
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242459126
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
| platform | system_bt | >= 10:0 < 10:2022-12-01 | 10:2022-12-01 |
| platform | system_bt | >= 11:0 < 11:2022-12-01 | 11:2022-12-01 |
| platform | system_bt | >= 12:0 < 12:2022-12-01 | 12:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2022-20483: Android Security Bulletin 2022-12-01
CVE: CVE-2022-20483
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-242459126
vendor_android·2022-12-01·CVSS 7.5
CVE-2022-20483 [HIGH] CVE-2022-20483: Android Security Bulletin 2022-12-01
CVE: CVE-2022-20483
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-242459126
Android Security Bulletin 2022-12-01
CVE: CVE-2022-20483
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-242459126
VulDB
Google Android 10.0/11.0/12.0/13.0 AVRC Response Parser avrc_pars_ct.cc out-of-bounds (A-242459126 / EUVD-2022-25743)
vuldb·2026-04-16·CVSS 7.5
CVE-2022-20483 [HIGH] Google Android 10.0/11.0/12.0/13.0 AVRC Response Parser avrc_pars_ct.cc out-of-bounds (A-242459126 / EUVD-2022-25743)
A vulnerability labeled as problematic has been found in Google Android 10.0/11.0/12.0/13.0. Affected is an unknown function of the file avrc_pars_ct.cc of the component AVRC Response Parser. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2022-20483. The attack can be executed remotely. There is not any exploit available.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-r5m2-pqwj-6px8: In several functions that parse avrc response in avrc_pars_ct
ghsa_unreviewed·2022-12-13
CVE-2022-20483 [HIGH] CWE-190 GHSA-r5m2-pqwj-6px8: In several functions that parse avrc response in avrc_pars_ct
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242459126
OSV
CVE-2022-20483: In several functions that parse avrc response in avrc_pars_ct
osv·2022-12-01
CVE-2022-20483 CVE-2022-20483: In several functions that parse avrc response in avrc_pars_ct
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-13
Published