Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-12-15 CVE-2021-1014 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2021-12-15 CVE-2021-1023 Information Exposure vulnerability in Google Android 12.0
In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-200
5.0
2021-12-15 CVE-2021-1024 Unspecified vulnerability in Google Android 12.0
In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a confused deputy.
local
low complexity
google
6.7
2021-12-15 CVE-2021-1025 Missing Authorization vulnerability in Google Android 12.0
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-12-15 CVE-2021-1026 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2021-12-15 CVE-2021-1030 Information Exposure Through Discrepancy vulnerability in Google Android 12.0
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure.
local
low complexity
google CWE-203
5.5
2021-12-15 CVE-2021-1038 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android
In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack.
local
low complexity
google CWE-1021
5.5
2021-12-15 CVE-2021-1041 Out-of-bounds Read vulnerability in Google Android
In (TBD) of (TBD), there is a possible out of bounds read due to memory corruption.
local
low complexity
google CWE-125
5.5
2021-12-15 CVE-2021-1042 Use After Free vulnerability in Google Android
In dsi_panel_debugfs_read_cmdset of dsi_panel.c, there is a possible disclosure of freed kernel heap memory due to a use after free.
local
low complexity
google CWE-416
4.4
2021-12-15 CVE-2021-1043 Unspecified vulnerability in Google Android
In TBD of TBD, there is a possible downgrade attack due to under utilized anti-rollback protections.
local
low complexity
google
5.5