Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2023-04-19 CVE-2023-21093 Path Traversal vulnerability in Google Android
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error.
local
low complexity
google CWE-22
7.8
2023-04-19 CVE-2023-21094 Missing Authorization vulnerability in Google Android
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check.
local
low complexity
google CWE-862
7.8
2023-04-19 CVE-2023-21096 Use After Free vulnerability in Google Android 12.0/12.1/13.0
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed.
network
low complexity
google CWE-416
critical
9.8
2023-04-19 CVE-2023-21097 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy.
local
low complexity
google CWE-610
7.8
2023-04-19 CVE-2023-21098 Unspecified vulnerability in Google Android
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy.
local
low complexity
google
7.8
2023-04-19 CVE-2023-21099 Unspecified vulnerability in Google Android
In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the background due to a logic error in the code.
local
low complexity
google
7.8
2023-04-19 CVE-2023-21100 Out-of-bounds Write vulnerability in Google Android 12.0/12.1/13.0
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2023-04-11 CVE-2022-47335 Classic Buffer Overflow vulnerability in Google Android
In telecom service, there is a missing permission check.
local
low complexity
google CWE-120
5.5
2023-04-11 CVE-2022-47336 Classic Buffer Overflow vulnerability in Google Android
In telecom service, there is a missing permission check.
local
low complexity
google CWE-120
5.5
2023-04-11 CVE-2022-47337 Out-of-bounds Write vulnerability in Google Android
In media service, there is a missing permission check.
local
low complexity
google CWE-787
5.5