Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2021-01-26 CVE-2020-0236 Out-of-bounds Read vulnerability in Google Android 10.0
In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation.
network
low complexity
google CWE-125
7.5
2021-01-11 CVE-2021-0319 Incorrect Authorization vulnerability in Google Android
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass.
local
low complexity
google CWE-863
7.3
2021-01-11 CVE-2021-0318 Use After Free vulnerability in Google Android
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free.
local
low complexity
google CWE-416
7.8
2021-01-11 CVE-2021-0317 Incorrect Authorization vulnerability in Google Android
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error.
local
low complexity
google CWE-863
7.8
2021-01-11 CVE-2021-0315 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-01-11 CVE-2021-0313 Improper Input Validation vulnerability in Google Android
In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation.
network
low complexity
google CWE-20
7.5
2021-01-11 CVE-2021-0310 Use After Free vulnerability in Google Android 11.0
In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2021-01-11 CVE-2021-0307 Unspecified vulnerability in Google Android 10.0/11.0
In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy.
local
low complexity
google
7.8
2021-01-11 CVE-2021-0306 Improper Privilege Management vulnerability in Google Android
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation.
local
low complexity
google CWE-269
7.8
2021-01-11 CVE-2021-0303 Use After Free vulnerability in Google Android 11.0
In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due to a race condition.
local
high complexity
google CWE-416
7.0