Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-11 CVE-2020-0140 Out-of-bounds Read vulnerability in Google Android 10.0
In rw_i93_sm_detect_ndef of rw_i93.c, there is a possible information disclosure due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2020-06-11 CVE-2020-0137 Missing Authorization vulnerability in Google Android 10.0
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-06-11 CVE-2020-0136 Integer Overflow or Wraparound vulnerability in Google Android 10.0
In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2020-06-11 CVE-2020-0133 Incorrect Default Permissions vulnerability in Google Android 10.0
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass.
local
low complexity
google CWE-276
7.3
2020-06-11 CVE-2020-0131 Out-of-bounds Write vulnerability in Google Android 10.0
In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data.
network
low complexity
google CWE-787
8.8
2020-06-11 CVE-2020-0129 Out-of-bounds Write vulnerability in Google Android 10.0
In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8
2020-06-11 CVE-2020-0128 Integer Overflow or Wraparound vulnerability in Google Android 10.0
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow.
network
low complexity
google CWE-190
7.5
2020-06-10 CVE-2020-0118 Out-of-bounds Write vulnerability in Google Android 10.0
In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation.
local
low complexity
google CWE-787
7.8
2020-06-10 CVE-2020-0115 Incorrect Authorization vulnerability in Google Android
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains.
local
low complexity
google CWE-863
7.8
2020-06-10 CVE-2020-0114 Unspecified vulnerability in Google Android 10.0
In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error.
local
low complexity
google
7.8