Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2021-01-11 CVE-2021-0322 Improper Input Validation vulnerability in Google Android 10.0/11.0/9.0
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation.
local
google CWE-20
1.9
2021-01-11 CVE-2021-0321 Information Exposure vulnerability in Google Android 11.0
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure.
local
low complexity
google CWE-200
2.1
2021-01-11 CVE-2021-0320 Race Condition vulnerability in Google Android 10.0/11.0
In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition.
local
google CWE-362
1.9
2021-01-11 CVE-2021-0319 Incorrect Authorization vulnerability in Google Android
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass.
local
google CWE-863
4.4
2021-01-11 CVE-2021-0318 USE After Free vulnerability in Google Android
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free.
local
low complexity
google CWE-416
7.2
2021-01-11 CVE-2021-0317 Improper Privilege Management vulnerability in Google Android
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error.
local
google CWE-269
4.4
2021-01-11 CVE-2021-0316 Out-Of-Bounds Write vulnerability in Google Android
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
critical
10.0
2021-01-11 CVE-2021-0315 Improper Restriction of Rendered UI Layers OR Frames vulnerability in Google Android
In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack.
4.4
2021-01-11 CVE-2021-0313 Improper Input Validation vulnerability in Google Android
In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation.
network
low complexity
google CWE-20
7.8
2021-01-11 CVE-2021-0312 Integer Overflow OR Wraparound vulnerability in Google Android
In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow.
network
google CWE-190
7.1