Vulnerabilities > Google > Android > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-11 | CVE-2021-0317 | Incorrect Authorization vulnerability in Google Android In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. | 7.8 |
2021-01-11 | CVE-2021-0315 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. | 7.3 |
2021-01-11 | CVE-2021-0313 | Improper Input Validation vulnerability in Google Android In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. | 7.5 |
2021-01-11 | CVE-2021-0310 | Use After Free vulnerability in Google Android 11.0 In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. | 7.8 |
2021-01-11 | CVE-2021-0307 | Unspecified vulnerability in Google Android 10.0/11.0 In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. | 7.8 |
2021-01-11 | CVE-2021-0306 | Improper Privilege Management vulnerability in Google Android In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. | 7.8 |
2021-01-11 | CVE-2021-0303 | Use After Free vulnerability in Google Android 11.0 In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a possible use after free due to a race condition. | 7.0 |
2021-01-11 | CVE-2020-27059 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window. | 7.8 |
2021-01-05 | CVE-2021-22492 | Classic Buffer Overflow vulnerability in Google Android An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetooth chipsets) software. | 8.8 |
2020-12-24 | CVE-2020-35693 | Unspecified vulnerability in Google Android On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without any user interaction, when the target device's Bluetooth is on, and it is running an app that offers a connectable BLE advertisement. low complexity google | 8.8 |