Vulnerabilities > Google > Android > Low

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2022-22267 Files or Directories Accessible to External Parties vulnerability in Google Android
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
local
low complexity
google CWE-552
2.1
2022-01-10 CVE-2022-22266 Improper Privilege Management vulnerability in Google Android 10.0/11.0/9.0
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
local
low complexity
google CWE-269
2.1
2022-01-10 CVE-2022-22264 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.
local
low complexity
google CWE-20
3.6
2022-01-10 CVE-2022-22263 Improper Privilege Management vulnerability in Google Android 11.0
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
local
low complexity
google CWE-269
2.1
2022-01-04 CVE-2022-20023 Missing Release of Resource after Effective Lifetime vulnerability in Google Android 10.0/11.0
In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet.
low complexity
google CWE-772
3.3
2022-01-04 CVE-2022-20022 Unspecified vulnerability in Google Android 10.0/11.0
In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD address as the currently connected BT host.
low complexity
google
3.3
2022-01-04 CVE-2022-20021 Unspecified vulnerability in Google Android 10.0/11.0
In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req.
low complexity
google
3.3
2022-01-04 CVE-2022-20018 Use of Uninitialized Resource vulnerability in Google Android 10.0/11.0/12.0
In seninf driver, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-908
2.1
2021-12-17 CVE-2021-0677 Integer Overflow or Wraparound vulnerability in Google Android 11.0
In ccu driver, there is a possible out of bounds read due to an integer overflow.
local
low complexity
google CWE-190
2.1
2021-12-15 CVE-2021-39657 Out-of-bounds Read vulnerability in Google Android
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1