Vulnerabilities > Google > Android > 14.0

DATE CVE VULNERABILITY TITLE RISK
2024-09-27 CVE-2024-39432 Out-of-bounds Write vulnerability in Google Android 12.0/13.0/14.0
In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check.
low complexity
google CWE-787
4.5
2024-09-27 CVE-2024-39433 Out-of-bounds Write vulnerability in Google Android 13.0/14.0
In drm service, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
4.4
2024-09-27 CVE-2024-39434 Out-of-bounds Read vulnerability in Google Android 13.0/14.0
In drm service, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2024-09-27 CVE-2024-39435 Unspecified vulnerability in Google Android 12.0/13.0/14.0
In Logmanager service, there is a possible missing verification incorrect input.
local
low complexity
google
7.8
2024-09-11 CVE-2024-40650 Missing Authorization vulnerability in Google Android
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state.
local
low complexity
google CWE-862
7.8
2024-09-11 CVE-2024-40652 Missing Authorization vulnerability in Google Android
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check.
local
low complexity
google CWE-862
7.8
2024-09-11 CVE-2024-40654 Incorrect Default Permissions vulnerability in Google Android
In multiple locations, there is a possible permission bypass due to a confused deputy.
local
low complexity
google CWE-276
7.8
2024-09-11 CVE-2024-40655 Unspecified vulnerability in Google Android
In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background due to a permissions bypass.
local
low complexity
google
7.8
2024-09-11 CVE-2024-40656 Unspecified vulnerability in Google Android
In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy.
local
low complexity
google
5.5
2024-09-11 CVE-2024-40657 Unspecified vulnerability in Google Android
In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy.
local
low complexity
google
7.8