Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-14 CVE-2020-0444 Release of Invalid Pointer or Reference vulnerability in Google Android
In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry.
local
low complexity
google CWE-763
7.8
2020-12-14 CVE-2020-0440 Missing Authorization vulnerability in Google Android 11.0
In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-12-14 CVE-2020-0099 Insecure Default Initialization of Resource vulnerability in Google Android
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value.
local
low complexity
google CWE-1188
7.8
2020-11-10 CVE-2020-0451 Out-of-bounds Write vulnerability in Google Android
In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow.
network
low complexity
google CWE-787
8.8
2020-11-10 CVE-2020-0449 Use After Free vulnerability in Google Android
In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free.
network
low complexity
google CWE-416
8.8
2020-11-10 CVE-2020-0442 Improper Input Validation vulnerability in Google Android
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation.
network
low complexity
google CWE-20
7.5
2020-11-10 CVE-2020-0441 Resource Exhaustion vulnerability in Google Android
In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation.
network
low complexity
google CWE-400
7.5
2020-11-10 CVE-2020-0439 Missing Authorization vulnerability in Google Android
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check.
local
low complexity
google CWE-862
7.8
2020-11-10 CVE-2020-0438 Missing Initialization of Resource vulnerability in Google Android 10.0/11.0
In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data.
local
low complexity
google CWE-909
7.8
2020-11-10 CVE-2020-0418 Unspecified vulnerability in Google Android 10.0
In getPermissionInfosForGroup of Utils.java, there is a logic error.
local
low complexity
google
7.8