Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2023-09-04 CVE-2023-38467 Out-of-bounds Write vulnerability in Google Android 11.0/12.0/13.0
In urild service, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
4.4
2023-09-04 CVE-2023-38468 Out-of-bounds Write vulnerability in Google Android 11.0/12.0/13.0
In urild service, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
4.4
2023-09-04 CVE-2023-38553 Out-of-bounds Write vulnerability in Google Android 11.0
In gnss service, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2023-09-04 CVE-2023-38554 Out-of-bounds Write vulnerability in Google Android 11.0/12.0/13.0
In wcn bsp driver, there is a possible out of bounds write due to a missing bounds check.This could lead to local denial of service with no additional execution privileges
local
low complexity
google CWE-787
5.5
2023-08-14 CVE-2023-21229 Unspecified vulnerability in Google Android 11.0/13.0
In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent.
local
low complexity
google
7.8
2023-08-14 CVE-2023-21230 Improper Check for Unusual or Exceptional Conditions vulnerability in Google Android 11.0/13.0
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure.
local
low complexity
google CWE-754
5.5
2023-08-14 CVE-2023-21231 Unspecified vulnerability in Google Android 13.0
In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check.
local
low complexity
google
7.8
2023-08-14 CVE-2023-21232 Unspecified vulnerability in Google Android 11.0/13.0
In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass.
local
low complexity
google
3.3
2023-08-14 CVE-2023-21233 Use of Uninitialized Resource vulnerability in Google Android 11.0
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data.
network
low complexity
google CWE-908
7.5
2023-08-14 CVE-2023-21234 Missing Authorization vulnerability in Google Android 11.0/13.0
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check.
local
low complexity
google CWE-862
5.5