Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-25387 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
network
low complexity
google CWE-119
7.5
2021-06-11 CVE-2021-25412 Unspecified vulnerability in Google Android 10.0
An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.
local
low complexity
google
7.2
2021-04-09 CVE-2021-25365 Improper Handling of Exceptional Conditions vulnerability in Google Android
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
local
low complexity
google CWE-755
7.2
2021-04-09 CVE-2021-25361 Unspecified vulnerability in Google Android 10.0/11.0
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
local
low complexity
google
7.2
2021-04-09 CVE-2021-25360 Out-of-bounds Write vulnerability in Google Android 10.0
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
network
low complexity
google CWE-787
7.5
2021-04-09 CVE-2021-25356 Incorrect Authorization vulnerability in Google Android
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.
local
low complexity
google CWE-863
7.2
2021-03-26 CVE-2021-25372 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
local
low complexity
google CWE-787
7.2
2021-03-26 CVE-2021-25371 Unspecified vulnerability in Google Android 10.0/11.0
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
local
low complexity
google
7.2
2021-03-10 CVE-2021-0455 Out-of-bounds Write vulnerability in Google Android
In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.2
2021-03-10 CVE-2021-0454 Out-of-bounds Write vulnerability in Google Android
In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.2