Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-10-06 CVE-2021-25477 Double Free vulnerability in Google Android 10.0/11.0/9.0
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.
network
low complexity
google CWE-415
4.9
2021-10-06 CVE-2021-25481 Improper Check for Unusual or Exceptional Conditions vulnerability in Google Android
An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.
local
low complexity
google CWE-754
6.7
2021-10-06 CVE-2021-25482 SQL Injection vulnerability in Google Android 11.0
SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.
local
low complexity
google CWE-89
4.4
2021-10-06 CVE-2021-25483 Out-of-bounds Read vulnerability in Google Android
Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.
network
low complexity
google CWE-125
6.5
2021-10-06 CVE-2021-25488 Out-of-bounds Read vulnerability in Google Android
Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.
local
low complexity
google CWE-125
5.5
2021-10-06 CVE-2021-25490 Unspecified vulnerability in Google Android 10.0/11.0/9.0
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
local
low complexity
google
6.0
2021-10-06 CVE-2021-25491 NULL Pointer Dereference vulnerability in Google Android 10.0/11.0/9.0
A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.
local
low complexity
google CWE-476
4.4
2021-10-06 CVE-2021-0644 Information Exposure vulnerability in Google Android 10.0/11.0
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check.
local
low complexity
google CWE-200
5.5
2021-10-06 CVE-2021-0680 Missing Authorization vulnerability in Google Android
In system properties, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-10-06 CVE-2021-0681 Missing Authorization vulnerability in Google Android
In system properties, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5