Vulnerabilities > Google > Android > 12.0

DATE CVE VULNERABILITY TITLE RISK
2021-12-15 CVE-2021-1026 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2021-12-15 CVE-2021-1027 Incorrect Type Conversion or Cast vulnerability in Google Android 12.0
In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting.
local
low complexity
google CWE-704
7.8
2021-12-15 CVE-2021-1028 Use After Free vulnerability in Google Android 12.0
In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free.
local
low complexity
google CWE-416
7.8
2021-12-15 CVE-2021-1029 Use After Free vulnerability in Google Android 12.0
In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free.
local
low complexity
google CWE-416
7.8
2021-12-15 CVE-2021-1030 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2021-12-15 CVE-2021-1031 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-1032 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
3.3
2021-12-15 CVE-2021-1034 Missing Authorization vulnerability in Google Android 12.0
In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check.
local
low complexity
google CWE-862
3.3
2021-12-15 CVE-2021-1038 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
5.5
2021-12-15 CVE-2021-1039 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8