Vulnerabilities > Google > Low

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-28784 Path Traversal vulnerability in Google Android 10.0/11.0/12.0
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user.
local
low complexity
google CWE-22
2.1
2022-05-03 CVE-2022-28783 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission.
local
low complexity
google CWE-20
3.6
2022-05-03 CVE-2022-28780 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission.
local
low complexity
google
2.1
2022-05-03 CVE-2022-20100 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
2.1
2022-05-03 CVE-2022-20098 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
2.1
2022-05-03 CVE-2022-20097 Race Condition vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a race condition.
local
google CWE-362
1.9
2022-05-03 CVE-2022-20096 Use of Uninitialized Resource vulnerability in Google Android
In camera, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-908
2.1
2022-05-03 CVE-2022-20092 Out-of-bounds Read vulnerability in Google Android 11.0/12.0
In alac decoder, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
2.1
2022-05-03 CVE-2021-22573 Improper Verification of Cryptographic Signature vulnerability in Google Oauth Client Library for Java
The vulnerability is that IDToken verifier does not verify if token is properly signed.
network
google CWE-347
3.5
2022-04-12 CVE-2021-39800 Use After Free vulnerability in Google Android
In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free.
local
low complexity
google CWE-416
2.1