Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Total 11915 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-21090 1 Google 1 Android 2023-04-25 N/A 5.0 MEDIUM
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259942609
CVE-2023-21091 1 Google 1 Android 2023-04-25 N/A 5.5 MEDIUM
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-257954050
CVE-2023-21096 1 Google 1 Android 2023-04-25 N/A 9.8 CRITICAL
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-254774758
CVE-2023-21098 1 Google 1 Android 2023-04-25 N/A 7.8 HIGH
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-260567867
CVE-2023-21099 1 Google 1 Android 2023-04-25 N/A 7.8 HIGH
In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-243377226
CVE-2023-20935 1 Google 1 Android 2023-04-25 N/A 5.5 MEDIUM
In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-256589724
CVE-2023-20909 1 Google 1 Android 2023-04-25 N/A 5.5 MEDIUM
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-243130512
CVE-2023-24513 5 Amazon, Arista, Equinix and 2 more 6 Aws Marketplace, Cloudeos, Dca-200-veos and 3 more 2023-04-24 N/A 7.5 HIGH
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
CVE-2021-22569 2 Google, Oracle 7 Google-protobuf, Protobuf-java, Protobuf-kotlin and 4 more 2023-04-18 4.3 MEDIUM 5.5 MEDIUM
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
CVE-2022-47335 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47336 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47337 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In media service, there is a missing permission check. This could lead to local denial of service in media service.
CVE-2022-47467 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47468 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47466 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47465 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
CVE-2022-47464 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47463 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47362 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47338 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-04-14 N/A 7.1 HIGH
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.