Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2022-20112 Improper Privilege Management vulnerability in Google Android
In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass.
local
low complexity
google CWE-269
5.5
2022-05-10 CVE-2022-20115 Missing Authorization vulnerability in Google Android 12.0/12.1
In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check.
local
low complexity
google CWE-862
5.5
2022-05-03 CVE-2022-20101 Path Traversal vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a path traversal.
local
low complexity
google CWE-22
5.5
2022-05-03 CVE-2022-20102 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
4.4
2022-05-03 CVE-2022-20103 Link Following vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to symbolic link following.
local
low complexity
google CWE-59
4.4
2022-05-03 CVE-2022-20104 Unspecified vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to improper access control.
local
low complexity
google
5.5
2022-05-03 CVE-2022-20105 Out-of-bounds Write vulnerability in multiple products
In MM service, there is a possible out of bounds write due to a stack-based buffer overflow.
local
low complexity
google linux CWE-787
6.7
2022-05-03 CVE-2022-20106 Out-of-bounds Write vulnerability in multiple products
In MM service, there is a possible out of bounds write due to a heap-based buffer overflow.
local
low complexity
google linux CWE-787
6.7
2022-05-03 CVE-2022-20107 Integer Overflow or Wraparound vulnerability in multiple products
In subtitle service, there is a possible application crash due to an integer overflow.
local
low complexity
google linux CWE-190
4.4
2022-05-03 CVE-2022-20108 Out-of-bounds Write vulnerability in multiple products
In voice service, there is a possible out of bounds write due to a stack-based buffer overflow.
local
low complexity
google linux CWE-787
6.7