Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-25459 Unspecified vulnerability in Google Android 10.0/11.0
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
local
low complexity
google
5.5
2021-09-09 CVE-2021-25460 Unspecified vulnerability in Google Android 10.0/11.0
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
local
low complexity
google
5.5
2021-09-09 CVE-2021-25462 NULL Pointer Dereference vulnerability in Google Android 10.0/11.0/9.0
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
local
low complexity
google CWE-476
5.5
2021-08-26 CVE-2021-30594 Use After Free vulnerability in multiple products
Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
low complexity
google fedoraproject CWE-416
6.8
2021-08-26 CVE-2021-30596 Origin Validation Error vulnerability in multiple products
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
network
low complexity
google fedoraproject CWE-346
4.3
2021-08-26 CVE-2021-30597 Use After Free vulnerability in multiple products
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
low complexity
google fedoraproject CWE-416
6.8
2021-08-18 CVE-2021-0407 Out-of-bounds Write vulnerability in Google Android 10.0/11.0
In clk driver, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
6.7
2021-08-18 CVE-2021-0408 Improper Check for Unusual or Exceptional Conditions vulnerability in Google Android 10.0/11.0
In asf extractor, there is a possible out of bounds read due to an incorrect bounds check.
local
low complexity
google CWE-754
5.5
2021-08-18 CVE-2021-0415 Missing Authorization vulnerability in Google Android 10.0/11.0
In memory management driver, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-08-18 CVE-2021-0416 Improper Input Validation vulnerability in Google Android 10.0/11.0
In memory management driver, there is a possible system crash due to improper input validation.
local
low complexity
google CWE-20
5.5