Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-06 CVE-2023-20685 Race Condition vulnerability in Google Android 12.0/13.0
In vdec, there is a possible use after free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20686 Race Condition vulnerability in Google Android 12.0/13.0
In display drm, there is a possible double free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20687 Race Condition vulnerability in Google Android 12.0/13.0
In display drm, there is a possible double free due to a race condition.
local
high complexity
google CWE-362
6.4
2023-04-06 CVE-2023-20688 Out-of-bounds Read vulnerability in Google Android 11.0/12.0/13.0
In power, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2023-04-06 CVE-2023-20677 Out-of-bounds Read vulnerability in multiple products
In wlan, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google yoctoproject linux CWE-125
4.4
2023-03-24 CVE-2022-20467 Unspecified vulnerability in Google Android
In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy.
local
low complexity
google
5.5
2023-03-24 CVE-2022-20499 Unspecified vulnerability in Google Android 12.0/12.1/13.0
In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed.
local
low complexity
google
5.5
2023-03-24 CVE-2022-42500 Improper Input Validation vulnerability in Google Android
In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation.
local
low complexity
google CWE-20
6.7
2023-03-24 CVE-2022-42528 Unspecified vulnerability in Google Android
In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code.
local
low complexity
google
5.5
2023-03-24 CVE-2023-20910 Resource Exhaustion vulnerability in Google Android
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion.
local
low complexity
google CWE-400
5.5