Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2018-05-10 CVE-2018-6246 Information Exposure vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure.
network
low complexity
google CWE-200
5.3
2018-05-10 CVE-2017-6293 Out-of-bounds Write vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges.
local
low complexity
google CWE-787
7.8
2018-05-10 CVE-2017-6289 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Trusted Execution Environment (TEE) contains a memory corruption (due to unusual root cause) vulnerability, which if run within the speculative execution of the TEE, may lead to local escalation of privileges.
local
low complexity
google CWE-119
7.8
2018-05-04 CVE-2018-10229 Information Exposure vulnerability in multiple products
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
network
high complexity
google mozilla lg CWE-200
4.8
2018-05-02 CVE-2013-6272 Improper Access Control vulnerability in Google Android
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
local
low complexity
google CWE-284
7.8
2018-04-26 CVE-2018-10237 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
network
high complexity
google redhat oracle CWE-770
5.9
2018-04-20 CVE-2014-0900 Improper Input Validation vulnerability in Google Android
The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.
network
low complexity
google CWE-20
8.8
2018-04-05 CVE-2017-0751 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm QCE driver.
local
low complexity
google
5.3
2018-04-05 CVE-2017-0748 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Qualcomm audio driver.
network
low complexity
google CWE-200
5.3
2018-04-05 CVE-2017-0744 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the NVIDIA firmware processing code.
local
low complexity
google
5.3