Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2019-2197 Insecure Default Initialization of Resource vulnerability in Google Android
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value.
local
low complexity
google CWE-1188
5.5
2019-11-13 CVE-2019-2196 SQL Injection vulnerability in Google Android
In Download Provider, there is possible SQL injection.
local
low complexity
google CWE-89
5.5
2019-10-11 CVE-2019-2187 Integer Underflow (Wrap or Wraparound) vulnerability in Google Android
In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow.
local
low complexity
google CWE-191
5.5
2019-10-11 CVE-2019-2183 Information Exposure vulnerability in Google Android 10.0/9.0
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization.
local
low complexity
google CWE-200
5.5
2019-10-11 CVE-2019-2110 Missing Authorization vulnerability in Google Android 9.0
In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a missing permission check.
local
low complexity
google CWE-862
5.5
2019-10-09 CVE-2019-11341 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Google Android 9.0
On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge.
low complexity
google CWE-327
4.6
2019-09-27 CVE-2019-9435 Out-of-bounds Read vulnerability in Google Android 10.0
In Bluetooth, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2019-09-27 CVE-2019-9434 Out-of-bounds Read vulnerability in Google Android 10.0
In Bluetooth, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
4.9
2019-09-27 CVE-2019-9433 Improper Input Validation vulnerability in multiple products
In libvpx, there is a possible information disclosure due to improper input validation.
6.5
2019-09-27 CVE-2019-9431 Use After Free vulnerability in Google Android 10.0
In Bluetooth, there is a possible out of bounds read due to a use after free.
network
low complexity
google CWE-416
4.9