Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2022-24932 Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
low complexity
google samsung
4.6
2022-03-10 CVE-2022-20049 Missing Authorization vulnerability in Google Android 10.0/11.0
In vpu, there is a possible escalation of privilege due to a missing permission check.
local
low complexity
google CWE-862
6.7
2022-03-10 CVE-2022-20050 Link Following vulnerability in Google Android 11.0/12.0
In connsyslogger, there is a possible symbolic link following due to improper link resolution.
local
low complexity
google CWE-59
6.7
2022-03-10 CVE-2022-20051 Improper Privilege Management vulnerability in Google Android 11.0/12.0
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment.
local
low complexity
google CWE-269
5.5
2022-03-10 CVE-2022-20055 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In preloader (usb), there is a possible out of bounds write due to a missing bounds check.
low complexity
google CWE-787
6.8
2022-03-10 CVE-2022-20056 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In preloader (usb), there is a possible out of bounds write due to a missing bounds check.
low complexity
google CWE-787
6.6
2022-03-10 CVE-2022-20057 Improper Handling of Exceptional Conditions vulnerability in Google Android 11.0/12.0
In btif, there is a possible memory corruption due to incorrect error handling.
local
low complexity
google CWE-755
6.5
2022-03-10 CVE-2022-20058 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In preloader (usb), there is a possible out of bounds write due to a missing bounds check.
low complexity
google CWE-787
6.6
2022-03-10 CVE-2022-20059 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In preloader (usb), there is a possible out of bounds write due to a missing bounds check.
low complexity
google CWE-787
6.6
2022-03-10 CVE-2022-20060 Missing Authentication for Critical Function vulnerability in Google Android 10.0/11.0/12.0
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication.
low complexity
google CWE-306
6.6