Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-02-03 CVE-2021-0357 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
In netdiag, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2021-02-03 CVE-2021-0356 Command Injection vulnerability in Google Android 10.0/11.0
In netdiag, there is a possible command injection due to improper input validation.
local
low complexity
google CWE-77
6.7
2021-02-03 CVE-2021-0355 Integer Overflow or Wraparound vulnerability in Google Android 11.0
In kisd, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
6.7
2021-02-03 CVE-2021-0354 Integer Overflow or Wraparound vulnerability in Google Android
In ged, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
6.7
2021-02-03 CVE-2021-0353 Out-of-bounds Write vulnerability in Google Android 11.0
In kisd, there is a possible memory corruption due to a heap buffer overflow.
local
low complexity
google CWE-787
6.7
2021-02-03 CVE-2021-0352 Type Confusion vulnerability in Google Android 10.0/11.0
In RT regmap driver, there is a possible memory corruption due to type confusion.
local
low complexity
google CWE-843
4.4
2021-01-26 CVE-2020-27098 Unspecified vulnerability in Google Android 11.0
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass.
local
low complexity
google
5.5
2021-01-26 CVE-2020-27097 Unspecified vulnerability in Google Android 11.0
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass.
local
low complexity
google
5.5
2021-01-11 CVE-2021-0322 Improper Input Validation vulnerability in Google Android 10.0/11.0/9.0
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation.
local
low complexity
google CWE-20
5.0
2021-01-11 CVE-2021-0321 Information Exposure Through Discrepancy vulnerability in Google Android 11.0
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure.
local
low complexity
google CWE-203
5.5