Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-12-17 CVE-2021-0901 Integer Overflow or Wraparound vulnerability in Google Android 10.0/11.0/12.0
In apusys, there is a possible memory corruption due to a missing bounds check.
local
low complexity
google CWE-190
6.7
2021-12-17 CVE-2021-0902 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
In apusys, there is a possible out of bounds read due to an incorrect bounds check.
local
low complexity
google CWE-125
4.4
2021-12-17 CVE-2021-0903 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/12.0
In apusys, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2021-12-15 CVE-2021-0650 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/9.0
In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check.
network
low complexity
google CWE-125
6.5
2021-12-15 CVE-2021-0653 Missing Authorization vulnerability in Google Android 10.0/11.0/9.0
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-12-15 CVE-2021-0704 Improper Preservation of Permissions vulnerability in Google Android 10.0/11.0/9.0
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass.
local
low complexity
google CWE-281
5.5
2021-12-15 CVE-2021-0904 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
In SRAMROM, there is a possible permission bypass due to an insecure permission setting.
local
low complexity
google CWE-732
6.7
2021-12-15 CVE-2021-0919 Integer Overflow or Wraparound vulnerability in Google Android 10.0/11.0/9.0
In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow.
local
low complexity
google CWE-190
5.0
2021-12-15 CVE-2021-0920 Use After Free vulnerability in multiple products
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition.
local
high complexity
google debian CWE-416
6.4
2021-12-15 CVE-2021-0931 Unspecified vulnerability in Google Android
In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data filtering.
local
low complexity
google
5.5