Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2021-02-10 CVE-2021-0327 Improper Privilege Management vulnerability in Google Android
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities.
local
low complexity
google CWE-269
7.8
2021-02-10 CVE-2021-0326 Out-of-bounds Write vulnerability in multiple products
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check.
7.5
2021-02-10 CVE-2021-0325 Out-of-bounds Write vulnerability in Google Android
In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow.
network
low complexity
google CWE-787
8.8
2021-02-10 CVE-2021-0314 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/8.1/9.0
In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-02-10 CVE-2021-0305 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/8.1/9.0
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value.
local
low complexity
google CWE-1021
7.8
2021-02-10 CVE-2021-0302 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/8.1/9.0
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value.
local
low complexity
google CWE-1021
7.8
2021-02-04 CVE-2021-0351 Unspecified vulnerability in Google Android
In wlan driver, there is a possible system crash due to a missing bounds check.
network
low complexity
google
7.5
2021-01-26 CVE-2020-0236 Out-of-bounds Read vulnerability in Google Android 10.0
In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation.
network
low complexity
google CWE-125
7.5
2021-01-11 CVE-2021-0319 Incorrect Authorization vulnerability in Google Android
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass.
local
low complexity
google CWE-863
7.3
2021-01-11 CVE-2021-0318 Use After Free vulnerability in Google Android
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free.
local
low complexity
google CWE-416
7.8