Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2021-03-10 CVE-2021-0385 Missing Authorization vulnerability in Google Android 11.0
In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks due to notification interaction above the lockscreen.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0383 Unspecified vulnerability in Google Android 11.0
In done of CaptivePortalLoginActivity.java, there is a confused deputy.
local
low complexity
google
7.8
2021-03-10 CVE-2021-0380 Missing Authorization vulnerability in Google Android 11.0
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission check.
local
low complexity
google CWE-862
7.8
2021-03-10 CVE-2021-0399 Use After Free vulnerability in Google Android
In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2021-03-10 CVE-2021-0398 Unspecified vulnerability in Google Android 11.0
In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy.
local
low complexity
google
7.8
2021-03-10 CVE-2021-0395 Use After Free vulnerability in Google Android 11.0
In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2021-03-10 CVE-2021-0393 Integer Overflow or Wraparound vulnerability in Google Android
In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2021-03-10 CVE-2021-0392 Double Free vulnerability in Google Android
In main of main.cpp, there is a possible memory corruption due to a double free.
local
low complexity
google CWE-415
7.8
2021-03-10 CVE-2021-0391 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, without permissions, due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
7.8
2021-03-10 CVE-2021-0390 Missing Authorization vulnerability in Google Android
In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check.
local
low complexity
google CWE-862
7.8