Vulnerabilities > Google > Android > 12l

DATE CVE VULNERABILITY TITLE RISK
2023-10-30 CVE-2023-21369 Unspecified vulnerability in Google Android
In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass.
local
low complexity
google
5.5
2023-10-30 CVE-2023-21370 Integer Overflow or Wraparound vulnerability in Google Android
In the Security Element API, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
6.7
2023-10-30 CVE-2023-21371 Integer Overflow or Wraparound vulnerability in Google Android
In Secure Element, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
6.7
2023-09-27 CVE-2023-44121 Unspecified vulnerability in Google Android
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file.
local
low complexity
google
6.3
2023-09-27 CVE-2023-44126 Unspecified vulnerability in Google Android
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device.
local
low complexity
google
5.5
2023-09-27 CVE-2023-44127 Unspecified vulnerability in Google Android
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device.
local
low complexity
google
5.5
2023-09-27 CVE-2023-44128 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Google Android
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app.
local
high complexity
google CWE-367
3.6
2023-09-27 CVE-2023-44129 Unspecified vulnerability in Google Android
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity.
local
low complexity
google
3.3
2022-12-08 CVE-2022-39912 Improper Handling of Exceptional Conditions vulnerability in Google Android
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
local
low complexity
google CWE-755
3.3
2022-12-08 CVE-2022-39913 Incorrect Authorization vulnerability in Google Android
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.
local
low complexity
google CWE-863
3.3