Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-10 CVE-2020-0048 Use of Uninitialized Resource vulnerability in Google Android 10.0
In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data.
local
low complexity
google CWE-908
5.5
2020-03-10 CVE-2020-0045 Out-of-bounds Write vulnerability in Google Android 10.0
In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race condition.
local
high complexity
google CWE-787
6.4
2020-03-10 CVE-2020-0061 Unspecified vulnerability in Google Android 10.0
In Pixel Recorder, there is a possible permissions bypass allowing arbitrary apps to record audio.
local
low complexity
google
5.5
2020-03-10 CVE-2020-0060 SQL Injection vulnerability in Google Android 10.0
In query of SmsProvider.java and MmsSmsProvider.java, there is a possible permission bypass due to SQL injection.
local
low complexity
google CWE-89
4.4
2020-03-10 CVE-2020-0059 Out-of-bounds Read vulnerability in Google Android 10.0
In btm_ble_batchscan_filter_track_adv_vse_cback of btm_ble_batchscan.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-03-10 CVE-2020-0058 Out-of-bounds Read vulnerability in Google Android 10.0
In l2c_rcv_acl_data of l2c_main.cc, there is a possible out of bounds read due to an incorrect bounds check.
local
low complexity
google CWE-125
4.4
2020-03-10 CVE-2020-0044 Out-of-bounds Read vulnerability in Google Android
In set_nonce of fpc_ta_qc_auth.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2020-03-10 CVE-2020-0043 Out-of-bounds Read vulnerability in Google Android
In authorize_enrol of fpc_ta_hw_auth.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2020-03-10 CVE-2020-0042 Out-of-bounds Read vulnerability in Google Android
In fpc_ta_hw_auth_unwrap_key of fpc_ta_hw_auth_qsee.c, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
4.4
2020-03-10 CVE-2020-0035 Missing Authorization vulnerability in Google Android 8.0/8.1/9.0
In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check.
local
low complexity
google CWE-862
5.5