Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2023-04-06 CVE-2023-20681 Out-of-bounds Write vulnerability in Google Android 12.0/13.0
In adsp, there is a possible out of bounds write due to improper input validation.
local
low complexity
google CWE-787
6.7
2023-04-06 CVE-2023-20682 Integer Overflow or Wraparound vulnerability in multiple products
In wlan, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google yoctoproject linux CWE-190
6.7
2023-04-06 CVE-2023-20684 Race Condition vulnerability in Google Android 12.0/13.0
In vdec, there is a possible use after free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20685 Race Condition vulnerability in Google Android 12.0/13.0
In vdec, there is a possible use after free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20686 Race Condition vulnerability in Google Android 12.0/13.0
In display drm, there is a possible double free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20687 Race Condition vulnerability in Google Android 12.0/13.0
In display drm, there is a possible double free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20688 Out-of-bounds Read vulnerability in Google Android 11.0/12.0/13.0
In power, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2023-04-06 CVE-2023-20677 Out-of-bounds Read vulnerability in multiple products
In wlan, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google yoctoproject linux CWE-125
4.4
2023-03-24 CVE-2022-20467 Unspecified vulnerability in Google Android
In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy.
local
low complexity
google
5.5
2023-03-24 CVE-2022-20499 Unspecified vulnerability in Google Android 12.0/12.1/13.0
In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed.
local
low complexity
google
5.5