Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-08-20 CVE-2019-2136 Out-of-bounds Read vulnerability in Google Android
In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation.
local
low complexity
google CWE-125
5.5
2019-08-20 CVE-2019-2135 Out-of-bounds Read vulnerability in Google Android
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2019-08-20 CVE-2019-2129 Out-of-bounds Read vulnerability in Google Android
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2019-08-08 CVE-2019-14783 Unspecified vulnerability in Google Android
On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files.
local
low complexity
google
5.5
2019-07-08 CVE-2019-2119 Improper Locking vulnerability in Google Android 8.0/8.1/9.0
In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking.
local
low complexity
google CWE-667
5.5
2019-07-08 CVE-2019-2118 Use of Uninitialized Resource vulnerability in Google Android 8.0/8.1/9.0
In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables.
local
low complexity
google CWE-908
5.5
2019-07-08 CVE-2019-2117 Missing Authorization vulnerability in Google Android
In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check.
local
low complexity
google CWE-862
5.5
2019-07-08 CVE-2019-2113 Unspecified vulnerability in Google Android 9.0
In setup wizard there is a bypass of some checks when wifi connection is skipped.
local
low complexity
google
5.5
2019-07-08 CVE-2019-2104 Use of Uninitialized Resource vulnerability in Google Android 8.0/8.1/9.0
In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields.
local
low complexity
google CWE-908
5.5
2019-06-19 CVE-2019-2022 Out-of-bounds Read vulnerability in Google Android
In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check.
network
low complexity
google CWE-125
6.5