Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-13 CVE-2024-32907 Classic Buffer Overflow vulnerability in Google Android
In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation.
local
low complexity
google CWE-120
7.8
2024-06-13 CVE-2024-32908 Race Condition vulnerability in Google Android
In sec_media_protect of media.c, there is a possible permission bypass due to a race condition.
local
low complexity
google CWE-362
7.8
2024-06-13 CVE-2024-32909 Out-of-bounds Write vulnerability in Google Android
In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow.
local
low complexity
google CWE-787
7.8
2024-05-07 CVE-2024-0024 Unspecified vulnerability in Google Android
In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation.
local
low complexity
google
7.8
2024-05-07 CVE-2024-0025 Unspecified vulnerability in Google Android
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error.
local
low complexity
google
7.8
2024-05-07 CVE-2024-0042 Improper Certificate Validation vulnerability in Google Android
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto.
local
low complexity
google CWE-295
7.8
2024-05-07 CVE-2024-0043 Unspecified vulnerability in Google Android
In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code.
local
low complexity
google
7.8
2024-05-07 CVE-2024-23704 Missing Authorization vulnerability in Google Android 13.0/14.0
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check.
local
low complexity
google CWE-862
7.8
2024-05-07 CVE-2024-23705 Unspecified vulnerability in Google Android
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation.
local
low complexity
google
7.8
2024-05-07 CVE-2024-23706 Unspecified vulnerability in Google Android 14.0
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation.
local
low complexity
google
7.8