Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-26 CVE-2021-21208 Improper Input Validation vulnerability in multiple products
Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code.
network
low complexity
google debian fedoraproject CWE-20
6.5
2021-04-23 CVE-2021-25382 Unspecified vulnerability in Google Android
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
low complexity
google
5.5
2021-04-15 CVE-2021-0488 Out-of-bounds Write vulnerability in Google Android
In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2021-04-13 CVE-2021-0471 Integer Overflow or Wraparound vulnerability in Google Android
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow.
local
low complexity
google CWE-190
5.5
2021-04-13 CVE-2021-0468 Insecure Default Initialization of Resource vulnerability in Google Android
In LK, there is a possible escalation of privilege due to an insecure default value.
low complexity
google CWE-1188
6.6
2021-04-13 CVE-2021-0444 Unspecified vulnerability in Google Android
In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent.
local
low complexity
google
5.5
2021-04-13 CVE-2021-0443 Race Condition vulnerability in Google Android
In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition.
local
high complexity
google CWE-362
4.7
2021-04-13 CVE-2021-0436 Integer Overflow or Wraparound vulnerability in Google Android
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow.
local
low complexity
google CWE-190
5.5
2021-04-13 CVE-2021-0428 Missing Authorization vulnerability in Google Android 10.0
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-04-13 CVE-2021-0400 Improper Input Validation vulnerability in Google Android 10.0/11.0/9.0
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation.
local
low complexity
google CWE-20
5.5