Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2020-0001 Unspecified vulnerability in Google Android
In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly.
local
low complexity
google
7.8
2020-01-06 CVE-2019-9469 Out-of-bounds Write vulnerability in Google Android
In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation.
local
low complexity
google CWE-787
7.8
2020-01-06 CVE-2019-9468 Double Free vulnerability in Google Android
In export_key_der of export_key.cpp, there is possible memory corruption due to a double free.
local
low complexity
google CWE-415
7.8
2019-12-06 CVE-2019-2232 Incorrect Calculation vulnerability in Google Android
In handleRun of TextLine.java, there is a possible application crash due to improper input validation.
network
low complexity
google CWE-682
7.5
2019-12-06 CVE-2019-2230 Use After Free vulnerability in Google Android 10.0
In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use after free.
network
low complexity
google CWE-416
7.5
2019-12-06 CVE-2019-2225 Improper Privilege Management vulnerability in Google Android
When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the user, and that device may be able to interact with the phone.
low complexity
google CWE-269
8.8
2019-12-06 CVE-2019-2223 Out-of-bounds Write vulnerability in Google Android
In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2019-12-06 CVE-2019-2222 Out-of-bounds Write vulnerability in Google Android
n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2019-12-06 CVE-2019-2221 Unspecified vulnerability in Google Android 10.0
In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state.
local
low complexity
google
7.8
2019-12-06 CVE-2019-2218 Missing Authorization vulnerability in Google Android 10.0
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check.
local
low complexity
google CWE-862
7.8