Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2018-04-26 CVE-2018-10237 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
network
high complexity
google redhat oracle CWE-770
5.9
2018-04-20 CVE-2014-0900 Improper Input Validation vulnerability in Google Android
The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.
network
low complexity
google CWE-20
6.5
2018-04-05 CVE-2017-0751 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm QCE driver.
local
low complexity
google
4.6
2018-04-05 CVE-2017-0748 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Qualcomm audio driver.
network
low complexity
google CWE-200
5.0
2018-04-05 CVE-2017-0744 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the NVIDIA firmware processing code.
local
low complexity
google
4.6
2018-04-05 CVE-2017-0431 Security vulnerability in Google Android Qualcomm components
An elevation of privilege vulnerability in Qualcomm closed source components.
local
low complexity
google
7.2
2018-04-05 CVE-2016-8482 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the NVIDIA GPU driver.
local
low complexity
google CWE-264
7.2
2018-04-05 CVE-2015-9016 Permissions, Privileges, and Access Controls vulnerability in Google Android
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request.
local
google CWE-264
6.9
2018-04-04 CVE-2017-6426 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Qualcomm SPMI driver.
network
google CWE-200
4.3
2018-04-04 CVE-2017-6425 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Qualcomm video driver.
network
google CWE-200
4.3