Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2022-02-09 CVE-2022-20028 Out-of-bounds Write vulnerability in Google Android
In Bluetooth, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2022-02-09 CVE-2022-20031 Use After Free vulnerability in Google Android 10.0/11.0
In fb driver, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2022-02-09 CVE-2022-20040 Out-of-bounds Write vulnerability in Google Android 11.0/12.0
In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow.
local
low complexity
google CWE-787
7.8
2022-02-09 CVE-2022-20041 Missing Authorization vulnerability in Google Android
In Bluetooth, there is a possible escalation of privilege due to a missing permission check.
local
low complexity
google CWE-862
7.8
2022-02-09 CVE-2022-20043 Missing Authorization vulnerability in Google Android
In Bluetooth, there is a possible escalation of privilege due to a missing permission check.
local
low complexity
google CWE-862
7.8
2022-02-09 CVE-2022-20044 Use After Free vulnerability in Google Android
In Bluetooth, there is a possible service crash due to a use after free.
local
low complexity
google CWE-416
7.8
2022-02-09 CVE-2022-20045 Use After Free vulnerability in Google Android
In Bluetooth, there is a possible service crash due to a use after free.
local
low complexity
google CWE-416
7.8
2022-01-14 CVE-2021-0959 Unspecified vulnerability in Google Android 12.0
In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in the code.
local
low complexity
google
7.8
2022-01-14 CVE-2021-1035 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 10.0/12.0
In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy.
local
low complexity
google CWE-610
7.8
2022-01-14 CVE-2021-1036 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8