Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-2061 Out-of-bounds Write vulnerability in Google Android 10.0
In libxaac, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2019-09-27 CVE-2019-2059 Out-of-bounds Write vulnerability in Google Android 10.0
In libxaac, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2019-09-27 CVE-2019-2055 Out-of-bounds Write vulnerability in Google Android 10.0
In libxaac, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2019-09-27 CVE-2018-9425 Improper Privilege Management vulnerability in Google Android 10.0
In Platform, there is a possible bypass of user interaction requirements due to missing permission checks.
local
low complexity
google CWE-269
7.8
2019-09-06 CVE-2019-9458 Use After Free vulnerability in multiple products
In the Android kernel in the video driver there is a use after free due to a race condition.
local
high complexity
google opensuse CWE-416
7.0
2019-09-06 CVE-2019-9345 Unspecified vulnerability in Google Android
In the Android kernel in sdcardfs there is a possible violation of the separation of data between profiles due to shared mapping of obb files.
local
low complexity
google
7.8
2019-09-06 CVE-2019-9270 Out-of-bounds Write vulnerability in Google Android
In the Android kernel in unifi and r8180 WiFi drivers there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2019-09-06 CVE-2019-2182 Unspecified vulnerability in Google Android
In the Android kernel in the kernel MMU code there is a possible execution path leaving some kernel text and rodata pages writable.
local
low complexity
google
7.8
2019-09-06 CVE-2018-6240 Out-of-bounds Write vulnerability in Google Android
NVIDIA Tegra contains a vulnerability in BootRom where a user with kernel level privileges can write an arbitrary value to an arbitrary physical address
local
low complexity
google CWE-787
7.8
2019-09-05 CVE-2019-9254 Command Injection vulnerability in Google Android 10.0
In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation.
local
low complexity
google CWE-77
7.8