Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-9383 Out-of-bounds Read vulnerability in Google Android 10.0
In NFC server, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.0
2019-09-27 CVE-2019-9380 Missing Authorization vulnerability in Google Android 10.0
In the settings UI, there is a possible spoofing vulnerability due to a missing permission check.
network
low complexity
google CWE-862
6.5
2019-09-27 CVE-2019-9379 Improper Input Validation vulnerability in Google Android 10.0
In libstagefright, there is a possible resource exhaustion due to a missing bounds check.
network
low complexity
google CWE-20
6.5
2019-09-27 CVE-2019-9376 Excessive Iteration vulnerability in Google Android 8.0/8.1/9.0
In Account of Account.java, there is a possible boot loop due to improper input validation.
local
low complexity
google CWE-834
5.5
2019-09-27 CVE-2019-9375 Out-of-bounds Write vulnerability in Google Android 10.0
In hostapd, there is a possible out of bounds write due to a race condition.
local
high complexity
google CWE-787
6.4
2019-09-27 CVE-2019-9373 Deserialization of Untrusted Data vulnerability in Google Android 10.0
In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute.
local
low complexity
google CWE-502
5.5
2019-09-27 CVE-2019-9372 Unchecked Return Value vulnerability in Google Android 10.0
In libskia, there is a possible crash due to a missing null check.
network
low complexity
google CWE-252
6.5
2019-09-27 CVE-2019-9371 Improper Input Validation vulnerability in multiple products
In libvpx, there is a possible resource exhaustion due to improper input validation.
6.5
2019-09-27 CVE-2019-9370 Out-of-bounds Read vulnerability in Google Android 10.0
In sonivox, there is a possible out of bounds read due to an incorrect bounds check.
network
low complexity
google CWE-125
6.5
2019-09-27 CVE-2019-9369 Use of Uninitialized Resource vulnerability in Google Android 10.0
In Bluetooth, there is a use of uninitialized variable.
local
low complexity
google CWE-908
5.5