Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2022-11-08 CVE-2022-20452 Unspecified vulnerability in Google Android 13.0
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy.
local
low complexity
google
7.8
2022-11-08 CVE-2022-20462 Out-of-bounds Write vulnerability in Google Android
In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2022-11-08 CVE-2022-32601 Deserialization of Untrusted Data vulnerability in Google Android 10.0/11.0/12.0
In telephony, there is a possible permission bypass due to a parcel format mismatch.
local
low complexity
google CWE-502
7.8
2022-10-14 CVE-2022-2985 Missing Authorization vulnerability in Google Android 10.0/11.0
In music service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-38669 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In soundrecorder service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-38670 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In soundrecorder service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-38698 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In messaging service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-39080 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In messaging service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-39107 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In Soundrecorder service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-39108 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In Music service, there is a missing permission check.
local
low complexity
google CWE-862
7.8