Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0362 Improper Input Validation vulnerability in Google Android 11.0
In libstagefright, there is a possible resource exhaustion due to improper input validation.
network
low complexity
google CWE-20
6.5
2020-09-17 CVE-2020-0361 Use of Uninitialized Resource vulnerability in Google Android 11.0
In libDRCdec, there is a possible information disclosure due to uninitialized data.
network
low complexity
google CWE-908
6.5
2020-09-17 CVE-2020-0359 Out-of-bounds Read vulnerability in Google Android 11.0
In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow.
local
low complexity
google CWE-125
5.5
2020-09-17 CVE-2020-0358 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Google Android 11.0
In SurfaceFlinger, there is a possible use after free due to a race condition.
local
high complexity
google CWE-367
6.4
2020-09-17 CVE-2020-0356 Out-of-bounds Write vulnerability in Google Android 11.0
In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
6.7
2020-09-17 CVE-2020-0355 Out-of-bounds Read vulnerability in Google Android 11.0
In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2020-09-17 CVE-2020-0353 Allocation of Resources Without Limits or Throttling vulnerability in Google Android 11.0
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check.
network
low complexity
google CWE-770
6.5
2020-09-17 CVE-2020-0352 SQL Injection vulnerability in Google Android 11.0
In MediaProvider, there is a possible permissions bypass due to SQL injection.
local
low complexity
google CWE-89
5.5
2020-09-17 CVE-2020-0351 Improper Input Validation vulnerability in Google Android 11.0
In libstagefright, there is possible CPU exhaustion due to improper input validation.
network
low complexity
google CWE-20
6.5
2020-09-17 CVE-2020-0344 SQL Injection vulnerability in Google Android 11.0
In MediaProvider, there is a possible permissions bypass due to SQL injection.
local
low complexity
google CWE-89
5.5