Vulnerabilities > Google > Android > Low

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-28786 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service.
local
low complexity
google CWE-125
2.1
2022-05-03 CVE-2022-28785 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service.
local
low complexity
google CWE-125
2.1
2022-05-03 CVE-2022-28784 Path Traversal vulnerability in Google Android 10.0/11.0/12.0
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user.
local
low complexity
google CWE-22
2.1
2022-05-03 CVE-2022-28783 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission.
local
low complexity
google CWE-20
3.6
2022-05-03 CVE-2022-28780 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission.
local
low complexity
google
2.1
2022-05-03 CVE-2022-20100 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
2.1
2022-05-03 CVE-2022-20098 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
2.1
2022-05-03 CVE-2022-20097 Race Condition vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a race condition.
local
google CWE-362
1.9
2022-05-03 CVE-2022-20096 Use of Uninitialized Resource vulnerability in Google Android
In camera, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-908
2.1
2022-05-03 CVE-2022-20092 Out-of-bounds Read vulnerability in Google Android 11.0/12.0
In alac decoder, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1