Vulnerabilities > Google > Android > 4.3

DATE CVE VULNERABILITY TITLE RISK
2022-12-08 CVE-2022-39914 Incorrect Authorization vulnerability in Google Android
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.
local
low complexity
google CWE-863
3.3
2022-03-04 CVE-2022-23729 Improper Authentication vulnerability in Google Android
When the device is in factory state, it can be access the shell without adb authentication process.
local
low complexity
google CWE-287
7.8
2022-01-21 CVE-2022-23728 Unspecified vulnerability in Google Android
Attacker can reset the device with AT Command in the process of rebooting the device.
low complexity
google
6.1
2020-12-24 CVE-2020-35693 Unspecified vulnerability in Google Android
On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without any user interaction, when the target device's Bluetooth is on, and it is running an app that offers a connectable BLE advertisement.
low complexity
google
8.8
2020-06-05 CVE-2020-13843 Unspecified vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01.
local
low complexity
google
5.5
2020-04-10 CVE-2015-9547 Information Exposure vulnerability in Google Android 4.3/4.4.2
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software.
network
low complexity
google CWE-200
7.5
2020-04-07 CVE-2016-11046 Improper Input Validation vulnerability in Google Android
An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software.
network
low complexity
google CWE-20
7.5
2020-02-21 CVE-2014-7914 Incorrect Authorization vulnerability in Google Android
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.
network
low complexity
google CWE-863
8.1
2020-02-07 CVE-2014-7224 Improper Input Validation vulnerability in Google Android
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.
network
low complexity
google CWE-20
8.8
2020-01-24 CVE-2015-1530 Integer Overflow or Wraparound vulnerability in Google Android
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.
local
low complexity
google CWE-190
7.8