Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-25456 Out-of-bounds Read vulnerability in Google Android
OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.
local
low complexity
google CWE-125
5.5
2021-09-09 CVE-2021-25458 NULL Pointer Dereference vulnerability in Google Android
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
local
low complexity
google CWE-476
5.5
2021-09-09 CVE-2021-25459 Unspecified vulnerability in Google Android 10.0/11.0
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
local
low complexity
google
5.5
2021-09-09 CVE-2021-25460 Unspecified vulnerability in Google Android 10.0/11.0
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
local
low complexity
google
5.5
2021-09-09 CVE-2021-25462 NULL Pointer Dereference vulnerability in Google Android 10.0/11.0/9.0
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
local
low complexity
google CWE-476
5.5
2021-08-18 CVE-2021-0407 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
In clk driver, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
6.7
2021-08-18 CVE-2021-0408 Improper Check for Unusual or Exceptional Conditions vulnerability in Google Android 10.0/11.0
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check.
local
low complexity
google CWE-754
5.5
2021-08-18 CVE-2021-0415 Missing Authorization vulnerability in Google Android 10.0/11.0
In memory management driver, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-08-18 CVE-2021-0416 Improper Input Validation vulnerability in Google Android 10.0/11.0
In memory management driver, there is a possible system crash due to improper input validation.
local
low complexity
google CWE-20
5.5
2021-08-18 CVE-2021-0417 Use of Insufficiently Random Values vulnerability in Google Android 10.0/11.0
In memory management driver, there is a possible system crash due to improper input validation.
local
low complexity
google CWE-330
5.5