Vulnerabilities > Google > Low

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2022-23594 Out-of-bounds Write vulnerability in Google Tensorflow 2.7.0
Tensorflow is an Open Source Machine Learning Framework.
local
low complexity
google CWE-787
2.1
2022-02-04 CVE-2022-0317 Improper Input Validation vulnerability in Google Go-Attestation
An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-formed Quote over no/some PCRs, causing AKPublic.Verify to succeed despite the inconsistency.
local
low complexity
google CWE-20
2.1
2022-01-14 CVE-2021-39680 Use of Uninitialized Resource vulnerability in Google Android
In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data.
local
low complexity
google CWE-908
2.1
2022-01-14 CVE-2021-39628 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0/11.0
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code.
local
low complexity
google CWE-668
2.1
2022-01-10 CVE-2022-22272 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
local
low complexity
google
3.3
2022-01-10 CVE-2022-22269 Files or Directories Accessible to External Parties vulnerability in Google Android 10.0/11.0/9.0
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
local
low complexity
google CWE-552
2.1
2022-01-10 CVE-2022-22268 Files or Directories Accessible to External Parties vulnerability in Google Android
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
local
low complexity
google CWE-552
3.6
2022-01-10 CVE-2022-22267 Files or Directories Accessible to External Parties vulnerability in Google Android
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
local
low complexity
google CWE-552
2.1
2022-01-10 CVE-2022-22266 Improper Privilege Management vulnerability in Google Android 10.0/11.0/9.0
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
local
low complexity
google CWE-269
2.1
2022-01-10 CVE-2022-22264 Improper Input Validation vulnerability in Google Android 10.0/11.0/12.0
Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.
local
low complexity
google CWE-20
3.6