Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-30 CVE-2021-39774 Out-of-bounds Read vulnerability in Google Android 12.0
In Bluetooth, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2022-03-30 CVE-2021-39775 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39777 Exposure of Resource to Wrong Sphere vulnerability in Google Android 12.0
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.
local
low complexity
google CWE-668
5.5
2022-03-30 CVE-2021-39778 Improper Input Validation vulnerability in Google Android 12.0
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation.
local
low complexity
google CWE-20
5.5
2022-03-30 CVE-2021-39779 Incorrect Default Permissions vulnerability in Google Android 12.0
In getCallStateUsingPackage of Telecom Service, there is a missing permission check.
local
low complexity
google CWE-276
5.5
2022-03-30 CVE-2021-39786 Out-of-bounds Write vulnerability in Google Android 12.0
In NFC, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2022-03-30 CVE-2021-39788 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-30 CVE-2021-39791 Information Exposure Through Discrepancy vulnerability in Google Android 12.1
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2022-03-29 CVE-2021-22572 Exposure of Resource to Wrong Sphere vulnerability in Google Data Transfer Project
On unix-like systems, the system temporary directory is shared between all users on that system.
local
low complexity
google CWE-668
5.5
2022-03-18 CVE-2021-22571 Incorrect Default Permissions vulnerability in Google Sa360 Webquery to Bigquery Exporter
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery.
local
low complexity
google CWE-276
5.5