Vulnerabilities > Google > Android > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-09-13 CVE-2022-20386 Unspecified vulnerability in Google Android
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
network
low complexity
google
critical
9.8
2022-09-13 CVE-2022-20385 Improper Validation of Specified Quantity in Input vulnerability in Google Android
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819
network
low complexity
google CWE-1284
critical
9.8
2022-09-13 CVE-2021-0942 Out-of-bounds Read vulnerability in Google Android
The path in this case is a little bit convoluted.
network
low complexity
google CWE-125
critical
9.8
2022-09-06 CVE-2022-26447 Out-of-bounds Write vulnerability in multiple products
In BT firmware, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google yoctoproject CWE-787
critical
9.8
2022-08-24 CVE-2022-20122 Use After Free vulnerability in Google Android
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls.
network
low complexity
google CWE-416
critical
9.8
2022-08-24 CVE-2021-39815 Use After Free vulnerability in Google Android
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls.
network
low complexity
google CWE-416
critical
9.8
2022-08-11 CVE-2022-20405 Unspecified vulnerability in Google Android
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
network
low complexity
google
critical
9.8
2022-08-11 CVE-2022-20403 Unspecified vulnerability in Google Android
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
network
low complexity
google
critical
9.8
2022-08-11 CVE-2022-20402 Unspecified vulnerability in Google Android
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
network
low complexity
google
critical
9.8
2022-08-11 CVE-2022-20400 Out-of-bounds Write vulnerability in Google Android
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
critical
9.8