Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-15 CVE-2019-2058 Out-of-bounds Read vulnerability in Google Android 10.0
In libAACdec, there is a possible out of bounds read.
network
low complexity
google CWE-125
6.5
2020-03-10 CVE-2020-0087 Incorrect Authorization vulnerability in Google Android 10.0
In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure.
local
low complexity
google CWE-863
5.5
2020-03-10 CVE-2020-0066 Out-of-bounds Write vulnerability in Google Android
In the netlink driver, there is a possible out of bounds write due to a race condition.
local
high complexity
google CWE-787
6.4
2020-03-10 CVE-2020-0057 Out-of-bounds Read vulnerability in Google Android 10.0
In btm_process_inq_results of btm_inq.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-03-10 CVE-2020-0056 Out-of-bounds Read vulnerability in Google Android 10.0
In btu_hcif_connection_comp_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-03-10 CVE-2020-0055 Out-of-bounds Read vulnerability in Google Android 10.0
In l2c_link_process_num_completed_pkts of l2c_link.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-03-10 CVE-2020-0053 Out-of-bounds Write vulnerability in Google Android 10.0
In convertHidlNanDataPathInitiatorRequestToLegacy, and convertHidlNanDataPathIndicationResponseToLegacy of hidl_struct_util.cpp, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
6.7
2020-03-10 CVE-2020-0052 Missing Authentication for Critical Function vulnerability in Google Android 10.0
In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass.
low complexity
google CWE-306
4.3
2020-03-10 CVE-2020-0050 Out-of-bounds Write vulnerability in Google Android 10.0
In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation.
local
low complexity
google CWE-787
6.7
2020-03-10 CVE-2020-0049 Use of Uninitialized Resource vulnerability in Google Android 10.0
In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data.
network
low complexity
google CWE-908
6.5