Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-13 CVE-2021-0426 Out-of-bounds Write vulnerability in Google Android 11.0
In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2021-04-09 CVE-2021-25365 Improper Handling of Exceptional Conditions vulnerability in Google Android
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
local
low complexity
google CWE-755
7.8
2021-04-09 CVE-2021-25361 Unspecified vulnerability in Google Android 10.0/11.0
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
local
low complexity
google
8.8
2021-04-09 CVE-2021-25356 Incorrect Authorization vulnerability in Google Android
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.
local
low complexity
google CWE-863
8.8
2021-04-06 CVE-2021-30162 Unspecified vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software.
local
low complexity
google
7.1
2021-03-10 CVE-2021-0465 Out-of-bounds Write vulnerability in Google Android
In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8
2021-03-10 CVE-2021-0464 Out-of-bounds Write vulnerability in Google Android
In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2021-03-10 CVE-2021-0389 Missing Authorization vulnerability in Google Android 11.0
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0388 Missing Authorization vulnerability in Google Android 11.0
In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0386 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value.
local
low complexity
google CWE-1021
7.8