Vulnerabilities > Google > Android > 12.1

DATE CVE VULNERABILITY TITLE RISK
2024-02-15 CVE-2023-40107 Use After Free vulnerability in Google Android
In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data.
local
low complexity
google CWE-416
7.8
2024-02-15 CVE-2023-40109 Unspecified vulnerability in Google Android
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass.
local
low complexity
google
7.8
2024-02-15 CVE-2023-40110 Out-of-bounds Write vulnerability in Google Android
In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2024-02-15 CVE-2023-40113 Missing Authorization vulnerability in Google Android
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check.
local
low complexity
google CWE-862
5.5
2024-02-15 CVE-2023-40114 Use After Free vulnerability in Google Android
In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free.
local
low complexity
google CWE-416
7.8
2024-02-15 CVE-2023-40115 Use After Free vulnerability in Google Android
In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2024-02-15 CVE-2023-40124 Out-of-bounds Read vulnerability in Google Android
In multiple locations, there is a possible cross-user read due to a confused deputy.
local
low complexity
google CWE-125
5.5
2023-12-04 CVE-2023-35668 Unspecified vulnerability in Google Android
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy.
local
low complexity
google
5.5
2023-12-04 CVE-2023-40073 Unspecified vulnerability in Google Android
In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy.
local
low complexity
google
5.5
2023-12-04 CVE-2023-40074 Unspecified vulnerability in Google Android
In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed.
local
low complexity
google
5.5