Vulnerabilities > Google > Android > Low

DATE CVE VULNERABILITY TITLE RISK
2020-02-12 CVE-2011-2343 Information Exposure vulnerability in Google Android
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
local
low complexity
google CWE-200
2.1
2020-01-08 CVE-2016-5346 Information Exposure vulnerability in Google Android
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).
local
low complexity
google CWE-200
2.1
2020-01-08 CVE-2020-0007 Use of Uninitialized Resource vulnerability in Google Android
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data.
local
low complexity
google CWE-908
2.1
2020-01-08 CVE-2020-0008 Out-of-bounds Read vulnerability in Google Android
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition.
local
google CWE-125
1.9
2020-01-08 CVE-2014-9908 Denial of Service vulnerability in Google Android 4.4/5.0.2/5.1.1
A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).
low complexity
google
3.3
2020-01-07 CVE-2019-9465 Unspecified vulnerability in Google Android
In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause.
local
low complexity
google
2.1
2020-01-06 CVE-2019-9472 Information Exposure vulnerability in Google Android
In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto.
local
low complexity
google CWE-200
2.1
2019-12-06 CVE-2019-2227 Out-of-bounds Read vulnerability in Google Android 10.0/9.0
In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting.
low complexity
google CWE-125
3.3
2019-12-06 CVE-2019-2229 Information Exposure vulnerability in Google Android
In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check.
local
low complexity
google CWE-200
2.1
2019-12-06 CVE-2019-2231 Missing Encryption of Sensitive Data vulnerability in Google Android 10.0/9.0
In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation.
local
low complexity
google CWE-311
2.1