Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-22 CVE-2021-0566 Out-of-bounds Read vulnerability in Google Android 11.0
In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2021-06-22 CVE-2021-0569 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
5.0
2021-06-22 CVE-2021-0572 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android 11.0
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-732
5.5
2021-06-21 CVE-2021-0504 Out-of-bounds Read vulnerability in Google Android 11.0
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check.
low complexity
google CWE-125
6.5
2021-06-21 CVE-2021-0521 Missing Authorization vulnerability in Google Android
In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-06-14 CVE-2021-0467 Out-of-bounds Write vulnerability in Google Android
In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check.
low complexity
google CWE-787
6.8
2021-06-11 CVE-2019-9475 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0
In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass.
local
low complexity
google CWE-668
5.5
2021-06-11 CVE-2021-0480 Unspecified vulnerability in Google Android
In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier.
local
low complexity
google
5.5
2021-06-11 CVE-2021-0484 Missing Initialization of Resource vulnerability in Google Android
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check.
local
low complexity
google CWE-909
5.5
2021-06-11 CVE-2021-25389 Improper Authentication vulnerability in Google Android 9.0
Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.
low complexity
google CWE-287
6.1