Vulnerabilities > Google > Android > 10.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-30 CVE-2023-21397 Unspecified vulnerability in Google Android
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value.
local
low complexity
google
7.8
2023-10-30 CVE-2023-21398 Unspecified vulnerability in Google Android
In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code.
local
low complexity
google
7.8
2023-10-30 CVE-2023-40101 Out-of-bounds Read vulnerability in Google Android
In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2023-10-30 CVE-2023-45780 Unspecified vulnerability in Google Android
In Print Service, there is a possible background activity launch due to a logic error in the code.
local
low complexity
google
7.3
2023-10-30 CVE-2021-39810 Missing Authorization vulnerability in Google Android
In NFC, there is a possible way to setup a default contactless payment app without user consent due to a missing permission check.
local
low complexity
google CWE-862
7.8
2023-10-30 CVE-2022-20264 Information Exposure Through Discrepancy vulnerability in Google Android
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21293 Information Exposure Through Discrepancy vulnerability in Google Android
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21294 Missing Authorization vulnerability in Google Android
In Slice, there is a possible disclosure of installed packages due to a missing permission check.
local
low complexity
google CWE-862
5.5
2023-10-30 CVE-2023-21295 Unspecified vulnerability in Google Android
In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check.
local
low complexity
google
5.5
2023-10-30 CVE-2023-21296 Information Exposure Through Discrepancy vulnerability in Google Android
In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5