Vulnerabilities > Google > Android > Low

DATE CVE VULNERABILITY TITLE RISK
2021-06-21 CVE-2021-0504 Out-of-bounds Read vulnerability in Google Android 11.0
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check.
low complexity
google CWE-125
3.3
2021-06-11 CVE-2021-0484 Missing Initialization of Resource vulnerability in Google Android
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check.
local
low complexity
google CWE-909
2.1
2021-06-11 CVE-2019-9475 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0
In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass.
local
low complexity
google CWE-668
2.1
2021-06-11 CVE-2021-25416 Improper Input Validation vulnerability in Google Android 10.0/11.0
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
local
low complexity
google CWE-20
2.1
2021-06-11 CVE-2021-25415 Improper Input Validation vulnerability in Google Android 10.0/11.0
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
local
low complexity
google CWE-20
2.1
2021-06-11 CVE-2021-25413 Unspecified vulnerability in Google Android 10.0/11.0/9.0
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.
local
low complexity
google
2.1
2021-06-11 CVE-2021-25411 Improper Input Validation vulnerability in Google Android 10.0/11.0
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.
local
low complexity
google CWE-20
2.1
2021-06-11 CVE-2021-25410 Incorrect Authorization vulnerability in Google Android 11.0
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.
local
low complexity
google CWE-863
3.6
2021-06-11 CVE-2021-25409 Missing Authorization vulnerability in Google Android 10.0
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.
local
low complexity
google CWE-862
2.1
2021-06-11 CVE-2021-25393 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android 10.0/11.0
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
local
low complexity
google CWE-732
2.1