Vulnerabilities > Google > Android > 11.0

DATE CVE VULNERABILITY TITLE RISK
2024-02-16 CVE-2024-0037 Missing Authorization vulnerability in Google Android
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check.
local
low complexity
google CWE-862
3.3
2024-02-16 CVE-2024-0040 Out-of-bounds Write vulnerability in Google Android
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow.
network
low complexity
google CWE-787
7.5
2024-02-15 CVE-2023-40100 Use After Free vulnerability in Google Android
In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2024-02-15 CVE-2023-40104 Improper Certificate Validation vulnerability in Google Android
In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates.
network
low complexity
google CWE-295
7.5
2024-02-15 CVE-2023-40105 Missing Authorization vulnerability in Google Android
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check.
local
low complexity
google CWE-862
5.5
2024-02-15 CVE-2023-40106 Unspecified vulnerability in Google Android
In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass.
local
low complexity
google
7.8
2024-02-15 CVE-2023-40109 Unspecified vulnerability in Google Android
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass.
local
low complexity
google
7.8
2024-02-15 CVE-2023-40110 Out-of-bounds Write vulnerability in Google Android
In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2024-02-15 CVE-2023-40112 Out-of-bounds Read vulnerability in Google Android 11.0
In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2024-02-15 CVE-2023-40113 Missing Authorization vulnerability in Google Android
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check.
local
low complexity
google CWE-862
5.5