Vulnerabilities > Google > Android > 12.1

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2022-20116 Unspecified vulnerability in Google Android 12.0/12.1
In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection.
local
low complexity
google
7.8
2022-04-12 CVE-2021-39794 Incorrect Default Permissions vulnerability in Google Android 11.0/12.0/12.1
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check.
local
low complexity
google CWE-276
7.8
2022-04-12 CVE-2021-39796 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2022-04-12 CVE-2021-39797 Improper Privilege Management vulnerability in Google Android 12.0/12.1
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code.
local
low complexity
google CWE-269
7.8
2022-04-12 CVE-2021-39798 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 12.0/12.1
In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check.
local
low complexity
google CWE-119
7.8
2022-04-12 CVE-2021-39799 Incorrect Authorization vulnerability in Google Android 12.0/12.1
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation.
local
low complexity
google CWE-863
7.8
2022-04-12 CVE-2021-39803 Use After Free vulnerability in Google Android
In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free.
network
low complexity
google CWE-416
6.5
2022-04-12 CVE-2021-39804 NULL Pointer Dereference vulnerability in Google Android 11.0/12.0/12.1
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check.
network
low complexity
google CWE-476
6.5
2022-04-12 CVE-2021-39805 Out-of-bounds Read vulnerability in Google Android 12.0/12.1
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check.
low complexity
google CWE-125
6.5
2022-04-12 CVE-2021-39807 Improper Privilege Management vulnerability in Google Android
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check.
local
low complexity
google CWE-269
7.8