Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-20098 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
4.4
2022-05-03 CVE-2022-20100 Missing Authorization vulnerability in Google Android 11.0/12.0
In aee daemon, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
4.4
2022-05-03 CVE-2022-28780 Unspecified vulnerability in Google Android 10.0/11.0/12.0
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission.
local
low complexity
google
5.5
2022-05-03 CVE-2022-28781 Improper Input Validation vulnerability in Google Android 11.0/12.0
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege.
local
low complexity
google CWE-20
6.7
2022-05-03 CVE-2022-28782 Unspecified vulnerability in Google Android 11.0/12.0
Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard.
low complexity
google
4.6
2022-05-03 CVE-2022-28785 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service.
local
low complexity
google CWE-125
5.5
2022-05-03 CVE-2022-28786 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service.
local
low complexity
google CWE-125
5.5
2022-05-03 CVE-2022-28787 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service.
local
low complexity
google CWE-125
5.5
2022-05-03 CVE-2022-28788 Out-of-bounds Read vulnerability in Google Android 10.0/11.0/12.0
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service.
local
low complexity
google CWE-125
5.5
2022-05-03 CVE-2022-0882 Unspecified vulnerability in Google Fuchsia 4.1
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT.
local
low complexity
google
5.5