Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-25 CVE-2021-0630 Integer Overflow or Wraparound vulnerability in Google Android
In wifi driver, there is a possible system crash due to a missing bounds check.
network
low complexity
google CWE-190
7.5
2021-10-25 CVE-2021-0631 Out-of-bounds Read vulnerability in Google Android
In wifi driver, there is a possible system crash due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2021-10-25 CVE-2021-0936 Use After Free vulnerability in Google Android
In acc_read of f_accessory.c, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2021-10-22 CVE-2021-0483 Use After Free vulnerability in Google Android 10.0/11.0
In multiple methods of AAudioService, there is a possible use-after-free due to a race condition.
local
low complexity
google CWE-416
7.8
2021-10-22 CVE-2021-0652 Race Condition vulnerability in Google Android
In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects.
local
low complexity
google CWE-362
7.8
2021-10-22 CVE-2021-0705 Unspecified vulnerability in Google Android 10.0/11.0
In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions.
local
low complexity
google
7.8
2021-10-22 CVE-2021-0708 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android
In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy.
local
low complexity
google CWE-610
7.8
2021-10-22 CVE-2021-0870 Race Condition vulnerability in Google Android
In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition.
network
high complexity
google CWE-362
8.1
2021-10-11 CVE-2021-0583 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/9.0
In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.3
2021-10-06 CVE-2021-25470 Unspecified vulnerability in Google Android 10.0/11.0/9.0
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
local
low complexity
google
7.9