Vulnerabilities > Google > Android > Low

DATE CVE VULNERABILITY TITLE RISK
2021-03-10 CVE-2021-0463 Out-of-bounds Read vulnerability in Google Android
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage.
local
google CWE-125
1.9
2021-03-10 CVE-2021-0374 Out-of-bounds Read vulnerability in Google Android 11.0
In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1
2021-03-10 CVE-2021-0375 Use of Insufficiently Random Values vulnerability in Google Android 11.0
In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default applications due to an insecure default value.
local
low complexity
google CWE-330
2.1
2021-03-10 CVE-2021-0377 Improper Input Validation vulnerability in Google Android 11.0
In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation.
local
low complexity
google CWE-20
2.1
2021-03-10 CVE-2021-0394 Out-of-bounds Read vulnerability in Google Android
In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1
2021-03-04 CVE-2021-25340 Unspecified vulnerability in Google Android 10.0
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
local
low complexity
google
2.1
2021-03-04 CVE-2021-25344 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.
local
low complexity
google CWE-276
2.1
2021-03-04 CVE-2021-25335 Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.
local
samsung google
1.9
2021-03-04 CVE-2021-25339 Improper Input Validation vulnerability in Google Android 10.0/11.0
Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory.
local
low complexity
google CWE-20
2.1
2021-02-26 CVE-2021-0403 Missing Authorization vulnerability in Google Android 11.0
In netdiag, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
2.1