Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0345 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 11.0
In DocumentsUI, there is a possible permission bypass due to a confused deputy.
local
low complexity
google CWE-610
7.8
2020-09-17 CVE-2020-0341 Missing Authorization vulnerability in Google Android 11.0
In DisplayManager, there is a possible permission bypass due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-09-17 CVE-2020-0321 Use of Uninitialized Resource vulnerability in Google Android 11.0
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data.
network
low complexity
google CWE-908
8.8
2020-09-17 CVE-2020-0306 Unspecified vulnerability in Google Android 11.0
In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation.
local
low complexity
google
7.8
2020-09-17 CVE-2020-0303 Improper Locking vulnerability in Google Android 11.0
In the Media extractor, there is a possible use after free due to improper locking.
network
low complexity
google CWE-667
8.8
2020-09-17 CVE-2020-0277 Missing Authorization vulnerability in Google Android 11.0
In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-09-17 CVE-2020-0275 Incorrect Default Permissions vulnerability in Google Android 11.0
In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass.
local
low complexity
google CWE-276
7.8
2020-09-17 CVE-2020-0267 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 11.0
In WindowManager, there is a possible launch of an unexpected app due to a confused deputy.
local
low complexity
google CWE-610
7.8
2020-09-17 CVE-2020-0266 Missing Authorization vulnerability in Google Android 11.0
In factory reset protection, there is a possible FRP bypass due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-09-17 CVE-2020-0264 Integer Overflow or Wraparound vulnerability in Google Android 11.0
In libstagefright, there is a possible out of bounds write due to an integer overflow.
network
low complexity
google CWE-190
8.8