Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0393 Out-of-bounds Read vulnerability in Google Android 10.0/9.0
In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-09-17 CVE-2020-0390 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
In the app zygote SE Policy, there is a possible permissions bypass.
local
low complexity
google CWE-276
5.5
2020-09-17 CVE-2020-0389 Unspecified vulnerability in Google Android 10.0/11.0
In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0386 Insecure Default Initialization of Resource vulnerability in Google Android
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value.
local
low complexity
google CWE-1188
5.5
2020-09-17 CVE-2020-0385 Out-of-bounds Write vulnerability in Google Android
In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
5.5
2020-09-17 CVE-2020-0384 Out-of-bounds Write vulnerability in Google Android
In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
5.5
2020-09-17 CVE-2020-0383 Out-of-bounds Write vulnerability in Google Android
In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
5.5
2020-09-17 CVE-2020-0379 Unspecified vulnerability in Google Android
In the Bluetooth service, there is a possible spoofing attack due to a logic error.
low complexity
google
5.7
2020-09-11 CVE-2020-25280 Unspecified vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software.
low complexity
google
6.8
2020-08-31 CVE-2020-25048 Missing Authentication for Critical Function vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software.
low complexity
google CWE-306
4.6