Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-09 CVE-2022-20034 Improper Certificate Validation vulnerability in Google Android 11.0
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation.
low complexity
google CWE-295
6.8
2022-02-09 CVE-2022-20035 Use After Free vulnerability in Google Android 10.0/11.0
In vcu driver, there is a possible information disclosure due to a use after free.
local
low complexity
google CWE-416
4.4
2022-02-09 CVE-2022-20036 Improper Input Validation vulnerability in Google Android 10.0/11.0
In ion driver, there is a possible information disclosure due to an incorrect bounds check.
local
low complexity
google CWE-20
5.5
2022-02-09 CVE-2022-20037 Improper Input Validation vulnerability in Google Android 10.0/11.0
In ion driver, there is a possible information disclosure due to an incorrect bounds check.
local
low complexity
google CWE-20
5.5
2022-02-09 CVE-2022-20038 Out-of-bounds Write vulnerability in Google Android 11.0
In ccu driver, there is a possible memory corruption due to an incorrect bounds check.
local
low complexity
google CWE-787
6.7
2022-02-09 CVE-2022-20039 Integer Overflow or Wraparound vulnerability in Google Android 11.0
In ccu driver, there is a possible memory corruption due to an integer overflow.
local
low complexity
google CWE-190
6.7
2022-02-09 CVE-2022-20042 Improper Handling of Exceptional Conditions vulnerability in Google Android
In Bluetooth, there is a possible information disclosure due to incorrect error handling.
local
low complexity
google CWE-755
5.5
2022-02-09 CVE-2022-20046 Memory Leak vulnerability in Google Android
In Bluetooth, there is a possible memory corruption due to a logic error.
local
low complexity
google CWE-401
5.5
2022-01-21 CVE-2022-23728 Unspecified vulnerability in Google Android
Attacker can reset the device with AT Command in the process of rebooting the device.
low complexity
google
6.1
2022-01-14 CVE-2021-1037 Missing Authorization vulnerability in Google Android
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it.
network
low complexity
google CWE-862
5.3