Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-16 CVE-2021-39713 Race Condition vulnerability in multiple products
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
local
high complexity
google debian CWE-362
7.0
2022-03-16 CVE-2021-39714 Use After Free vulnerability in Google Android
In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow.
local
low complexity
google CWE-416
7.8
2022-03-16 CVE-2021-39716 Unspecified vulnerability in Google Android
Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A
network
low complexity
google
7.5
2022-03-16 CVE-2021-39726 Out-of-bounds Read vulnerability in Google Android
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to an incorrect bounds check.
network
low complexity
google CWE-125
7.5
2022-03-16 CVE-2021-39732 Integer Overflow or Wraparound vulnerability in Google Android
In copy_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2022-03-16 CVE-2021-39734 Missing Authorization vulnerability in Google Android
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check.
local
low complexity
google CWE-862
7.8
2022-03-16 CVE-2021-39793 Out-of-bounds Write vulnerability in Google Android
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code.
local
low complexity
google CWE-787
7.8
2022-03-10 CVE-2022-25814 Unspecified vulnerability in Google Android 11.0/12.0
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
local
low complexity
google
7.8
2022-03-10 CVE-2022-25815 Unspecified vulnerability in Google Android 10.0/11.0
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
local
low complexity
google
7.8
2022-03-10 CVE-2022-25821 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
local
low complexity
google CWE-125
7.1