Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-13 CVE-2022-20227 Out-of-bounds Read vulnerability in Google Android
In USB driver, there is a possible out of bounds read due to a heap buffer overflow.
local
low complexity
google CWE-125
5.5
2022-07-13 CVE-2022-20228 Use After Free vulnerability in Google Android 12.0/12.1
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free.
network
low complexity
google CWE-416
6.5
2022-07-13 CVE-2022-20230 Improper Encoding or Escaping of Output vulnerability in Google Android
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation.
local
low complexity
google CWE-116
5.5
2022-07-12 CVE-2022-30758 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0/12.0
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.
local
low complexity
google CWE-276
5.5
2022-07-12 CVE-2022-33685 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.
local
low complexity
google
5.5
2022-07-12 CVE-2022-33691 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Google Android 10.0/11.0/12.0
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.
local
high complexity
google CWE-367
4.7
2022-07-12 CVE-2022-33702 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
local
low complexity
google
5.5
2022-07-06 CVE-2022-21763 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In telecom service, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2022-07-06 CVE-2022-21764 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In telecom service, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2022-07-06 CVE-2022-21765 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In CCCI, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7