Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2020-10-14 CVE-2020-0423 Improper Locking vulnerability in multiple products
In binder_release_work of binder.c, there is a possible use-after-free due to improper locking.
local
low complexity
google debian CWE-667
7.8
2020-10-14 CVE-2020-0421 Improper Handling of Exceptional Conditions vulnerability in Google Android
In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling.
local
low complexity
google CWE-755
7.8
2020-10-14 CVE-2020-0420 Missing Authorization vulnerability in Google Android 11.0
In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-10-14 CVE-2020-0416 Insecure Default Initialization of Resource vulnerability in Google Android
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value.
network
low complexity
google CWE-1188
8.8
2020-10-14 CVE-2020-0413 Out-of-bounds Read vulnerability in Google Android
In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2020-10-14 CVE-2020-0408 Integer Overflow or Wraparound vulnerability in Google Android
In remove of String16.cpp, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2020-10-14 CVE-2020-0377 Out-of-bounds Read vulnerability in Google Android
In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2020-10-14 CVE-2019-2194 Incorrect Type Conversion or Cast vulnerability in Google Android 9.0
In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution due to improper casting.
local
low complexity
google CWE-704
7.8
2020-10-06 CVE-2020-26606 Unspecified vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software.
network
low complexity
google
7.5
2020-10-06 CVE-2020-26605 Information Exposure Through Log Files vulnerability in Google Android 10.0/11.0
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software.
network
low complexity
google CWE-532
7.5