Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2022-03-16 CVE-2021-39734 Missing Authorization vulnerability in Google Android
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check.
local
low complexity
google CWE-862
4.6
2022-03-16 CVE-2021-39735 Race Condition vulnerability in Google Android
In gasket_alloc_coherent_memory of gasket_page_table.c, there is a possible memory corruption due to a race condition.
local
google CWE-362
4.4
2022-03-16 CVE-2021-39736 Integer Overflow or Wraparound vulnerability in Google Android
In prepare_io_entry and prepare_response of lwis_ioctl.c and lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
4.6
2022-03-16 CVE-2021-39737 Unspecified vulnerability in Google Android
Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A
network
low complexity
google
critical
10.0
2022-03-16 CVE-2021-39792 Race Condition vulnerability in Google Android
In usb_gadget_giveback_request of core.c, there is a possible use after free out of bounds read due to a race condition.
local
google CWE-362
1.9
2022-03-16 CVE-2021-39793 Out-of-bounds Write vulnerability in Google Android
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code.
local
low complexity
google CWE-787
7.2
2022-03-10 CVE-2022-25814 Unspecified vulnerability in Google Android 11.0/12.0
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
local
low complexity
google
4.6
2022-03-10 CVE-2022-25815 Unspecified vulnerability in Google Android 10.0/11.0
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
local
low complexity
google
4.6
2022-03-10 CVE-2022-25816 Improper Authentication vulnerability in Google Android 10.0/11.0/12.0
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
local
low complexity
google CWE-287
2.1
2022-03-10 CVE-2022-25817 Unspecified vulnerability in Google Android 10.0/11.0
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.
local
low complexity
google
3.3