Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-06-11 CVE-2020-0135 Missing Authorization vulnerability in Google Android 10.0
In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check.
local
low complexity
google CWE-862
4.4
2020-06-11 CVE-2020-0134 Missing Initialization of Resource vulnerability in Google Android 10.0
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-909
5.5
2020-06-11 CVE-2020-0132 Deserialization of Untrusted Data vulnerability in Google Android 10.0
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization.
local
low complexity
google CWE-502
5.5
2020-06-11 CVE-2020-0127 Out-of-bounds Read vulnerability in Google Android 10.0
In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2020-06-11 CVE-2020-0126 Use After Free vulnerability in Google Android 10.0
In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition.
local
high complexity
google CWE-416
6.4
2020-06-11 CVE-2020-0124 Out-of-bounds Write vulnerability in Google Android 10.0
In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2020-06-10 CVE-2020-0121 Unspecified vulnerability in Google Android 10.0
In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error.
local
low complexity
google
5.5
2020-06-10 CVE-2020-0119 Improper Certificate Validation vulnerability in Google Android 10.0
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation.
network
high complexity
google CWE-295
5.3
2020-06-10 CVE-2020-0116 Unspecified vulnerability in Google Android 10.0
In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass.
local
low complexity
google
5.5
2020-06-10 CVE-2020-0113 Use After Free vulnerability in Google Android 10.0
In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free.
local
low complexity
google CWE-416
5.5