Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2023-05-15 CVE-2023-21104 Incorrect Default Permissions vulnerability in Google Android 12.1/13.0
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed.
local
low complexity
google CWE-276
5.5
2023-05-15 CVE-2023-21106 Double Free vulnerability in Google Android
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free.
local
low complexity
google CWE-415
7.8
2023-05-15 CVE-2023-21107 Incorrect Default Permissions vulnerability in Google Android
In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check.
local
low complexity
google CWE-276
7.8
2023-05-15 CVE-2023-21109 Unspecified vulnerability in Google Android
In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code.
local
low complexity
google
7.8
2023-05-15 CVE-2023-21110 Resource Exhaustion vulnerability in Google Android
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion.
local
low complexity
google CWE-400
7.8
2023-05-15 CVE-2023-21111 Improper Input Validation vulnerability in Google Android
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation.
local
low complexity
google CWE-20
5.5
2023-05-15 CVE-2023-21112 Out-of-bounds Read vulnerability in Google Android
In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2023-05-15 CVE-2023-21116 Unspecified vulnerability in Google Android
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code.
local
low complexity
google
6.7
2023-05-15 CVE-2023-21117 Unspecified vulnerability in Google Android 13.0
In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to a permissions bypass.
local
low complexity
google
7.8
2023-05-15 CVE-2023-21118 Out-of-bounds Read vulnerability in Google Android
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow.
local
low complexity
google CWE-125
5.5