Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-30 CVE-2021-39779 Incorrect Default Permissions vulnerability in Google Android 12.0
In getCallStateUsingPackage of Telecom Service, there is a missing permission check.
local
low complexity
google CWE-276
5.5
2022-03-30 CVE-2021-39786 Out-of-bounds Write vulnerability in Google Android 12.0
In NFC, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2022-03-30 CVE-2021-39788 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39791 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-16 CVE-2021-39624 Unspecified vulnerability in Google Android
In PackageManager, there is a possible permanent denial of service due to resource exhaustion.
local
low complexity
google
5.5
2022-03-16 CVE-2021-39667 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overflow.
network
low complexity
google CWE-787
6.5
2022-03-16 CVE-2021-39689 Insufficient Verification of Data Authenticity vulnerability in Google Android 12.0
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code.
local
low complexity
google CWE-345
6.7
2022-03-16 CVE-2021-39690 Improper Validation of Specified Quantity in Input vulnerability in Google Android 12.0
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation.
local
low complexity
google CWE-1284
5.5
2022-03-16 CVE-2021-39711 Out-of-bounds Read vulnerability in Google Android
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value.
local
low complexity
google CWE-125
4.4
2022-03-16 CVE-2021-39712 Race Condition vulnerability in Google Android
In TBD of TBD, there is a possible user after free vulnerability due to a race condition.
local
high complexity
google CWE-362
6.4