Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2021-03-10 CVE-2021-0395 Use After Free vulnerability in Google Android 11.0
In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2021-03-10 CVE-2021-0393 Integer Overflow or Wraparound vulnerability in Google Android
In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2021-03-10 CVE-2021-0392 Double Free vulnerability in Google Android
In main of main.cpp, there is a possible memory corruption due to a double free.
local
low complexity
google CWE-415
7.8
2021-03-10 CVE-2021-0391 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, without permissions, due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2021-03-10 CVE-2021-0390 Missing Authorization vulnerability in Google Android
In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0376 Incorrect Authorization vulnerability in Google Android 11.0
In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass.
local
low complexity
google CWE-863
7.8
2021-03-10 CVE-2021-0372 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android 11.0
In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-732
7.8
2021-03-10 CVE-2021-0369 Unspecified vulnerability in Google Android 11.0
In CrossProfileAppsServiceImpl.java, there is the possibility of an application's INTERACT_ACROSS_PROFILES grant state not displaying properly in the setting UI due to a logic error in the code.
local
low complexity
google
7.8
2021-03-10 CVE-2020-0025 Unspecified vulnerability in Google Android 11.0
In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a permissions bypass.
local
low complexity
google
7.8
2021-03-04 CVE-2021-25337 Unspecified vulnerability in Google Android 10.0/11.0/9.0
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
local
low complexity
google
7.1