Vulnerabilities > Google > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-16 CVE-2021-39717 Out-of-bounds Read vulnerability in Google Android
In iaxxx_btp_write_words of iaxxx-btp.c, there is a possible out of bounds read due to an incorrect bounds check.
local
low complexity
google CWE-125
2.1
2022-03-16 CVE-2021-39711 Out-of-bounds Read vulnerability in Google Android
In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value.
local
low complexity
google CWE-125
2.1
2022-03-10 CVE-2022-25821 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
local
low complexity
google CWE-125
3.6
2022-03-10 CVE-2022-25820 Improper Restriction of Excessive Authentication Attempts vulnerability in Google Android 11.0/12.0
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.
local
low complexity
google CWE-307
2.1
2022-03-10 CVE-2022-25819 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.
local
low complexity
google CWE-125
2.1
2022-03-10 CVE-2022-25817 Unspecified vulnerability in Google Android 10.0/11.0
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.
local
low complexity
google
3.3
2022-03-10 CVE-2022-25816 Improper Authentication vulnerability in Google Android 10.0/11.0/12.0
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
local
low complexity
google CWE-287
2.1
2022-03-10 CVE-2022-24929 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
local
low complexity
google
2.1
2022-03-10 CVE-2022-20051 Improper Privilege Management vulnerability in Google Android 11.0/12.0
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment.
local
low complexity
google CWE-269
2.1
2022-02-25 CVE-2022-25327 Incorrect Default Permissions vulnerability in Google Fscrypt
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in.
local
low complexity
google CWE-276
2.1