Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-30 CVE-2023-21382 Missing Authorization vulnerability in Google Android
In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check.
local
low complexity
google CWE-862
5.5
2023-10-30 CVE-2023-21383 Unspecified vulnerability in Google Android
In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt.
local
low complexity
google
5.5
2023-10-30 CVE-2023-21384 Unspecified vulnerability in Google Android
In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2023-10-30 CVE-2023-21385 Out-of-bounds Write vulnerability in Google Android
In Whitechapel, there is a possible out of bounds read due to memory corruption.
local
low complexity
google CWE-787
5.5
2023-10-30 CVE-2023-21387 Information Exposure Through Log Files vulnerability in Google Android
In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure.
local
low complexity
google CWE-532
4.4
2023-10-30 CVE-2023-21394 Unspecified vulnerability in Google Android
In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check.
local
low complexity
google
5.5
2023-10-30 CVE-2023-21395 Use After Free vulnerability in Google Android
In Bluetooth, there is a possible out of bounds read due to a use after free.
low complexity
google CWE-416
6.5
2023-10-30 CVE-2023-40101 Out-of-bounds Read vulnerability in Google Android
In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2023-10-30 CVE-2022-20264 Information Exposure Through Discrepancy vulnerability in Google Android
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2023-10-30 CVE-2023-21293 Information Exposure Through Discrepancy vulnerability in Google Android
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5