Vulnerabilities > Google > Android > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-06-15 CVE-2022-20145 Unspecified vulnerability in Google Android 11.0
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack.
network
low complexity
google
critical
9.8
2022-06-15 CVE-2022-20140 Out-of-bounds Write vulnerability in Google Android 12.0/12.1
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check.
network
low complexity
google CWE-787
critical
9.8
2022-06-15 CVE-2022-20130 Improper Check for Unusual or Exceptional Conditions vulnerability in Google Android
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow.
network
low complexity
google CWE-754
critical
9.8
2022-06-15 CVE-2022-20127 Double Free vulnerability in Google Android
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.
network
low complexity
google CWE-415
critical
9.8
2022-06-07 CVE-2022-30722 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
network
low complexity
google
critical
9.8
2022-06-07 CVE-2022-30713 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
network
low complexity
google CWE-20
critical
9.1
2022-06-07 CVE-2022-30712 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
network
low complexity
google CWE-20
critical
9.1
2022-06-07 CVE-2022-30711 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
network
low complexity
google CWE-20
critical
9.1
2022-06-07 CVE-2022-30710 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
network
low complexity
google CWE-20
critical
9.1
2022-05-10 CVE-2022-20120 Unspecified vulnerability in Google Android
Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A
network
low complexity
google
critical
9.8