Platform Packages Providers Contactsprovider vulnerabilities
6 known vulnerabilities affecting platform/packages_providers_contactsprovider.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN6
Vulnerabilities
Page 1 of 1
CVE-2022-20505UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20505 CVE-2022-20505: In openFile of CallLogProvider
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation
osv
CVE-2022-20351UNKNOWN≥ 10:0, < 10:2022-10-01≥ 11:0, < 11:2022-10-01+2 more2022-10-01
CVE-2022-20351 CVE-2022-20351: In queryInternal of CallLogProvider
In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20220UNKNOWN≥ 12:0, < 12:2022-07-05≥ 12L:0, < 12L:2022-07-052022-07-01
CVE-2022-20220 CVE-2022-20220: In openFile of CallLogProvider
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0428UNKNOWN≥ 10:0, < 10:2021-09-012021-09-01
CVE-2021-0428 CVE-2021-0428: In getSimSerialNumber of TelephonyManager
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0368UNKNOWN≥ 11:0, < 11:2021-07-052021-07-01
CVE-2020-0368 CVE-2020-0368: In queryInternal of CallLogProvider
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0569UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0569 CVE-2021-0569: In onStart of ContactsDumpActivity
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
osv