Vulnerabilities > Google > Android > Low

DATE CVE VULNERABILITY TITLE RISK
2019-02-28 CVE-2019-1995 Information Exposure vulnerability in Google Android
In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach files to an email due to a confused deputy.
local
low complexity
google CWE-200
2.1
2019-02-28 CVE-2019-1996 Out-of-bounds Read vulnerability in Google Android 8.0/8.1/9.0
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check.
low complexity
google CWE-125
3.3
2019-02-28 CVE-2019-2001 Information Exposure vulnerability in Google Android
The permissions on /proc/iomem were world-readable.
local
low complexity
google CWE-200
2.1
2019-02-11 CVE-2018-9588 Out-of-bounds Read vulnerability in Google Android
In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check.
low complexity
google CWE-125
3.3
2019-02-11 CVE-2018-9589 Out-of-bounds Read vulnerability in Google Android
In ieee802_11_rx_wnmsleep_req of wnm_ap.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1
2019-02-11 CVE-2018-9593 Out-of-bounds Read vulnerability in Google Android
In llcp_dlc_proc_i_pdu of llcp_dlc.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an incorrect bounds check.
low complexity
google CWE-125
3.3
2019-02-11 CVE-2018-9594 Out-of-bounds Read vulnerability in Google Android
In llcp_link_proc_agf_pdu of llcp_link.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an integer overflow.
low complexity
google CWE-125
3.3
2019-02-11 CVE-2018-12006 Information Exposure vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized padding present in display function.
local
low complexity
google CWE-200
2.1
2019-02-11 CVE-2018-12011 Use of Uninitialized Resource vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.
local
low complexity
google CWE-908
2.1
2018-12-07 CVE-2017-15835 Infinite Loop vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE length more than 255, an infinite loop may potentially occur resulting in a denial of service.
low complexity
google CWE-835
3.3