Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-14 CVE-2020-0460 Improper Authentication vulnerability in Google Android 11.0
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error.
network
low complexity
google CWE-287
7.5
2020-12-14 CVE-2020-0458 Integer Overflow or Wraparound vulnerability in Google Android
In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2020-12-14 CVE-2020-0444 Release of Invalid Pointer or Reference vulnerability in Google Android
In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry.
local
low complexity
google CWE-763
7.8
2020-12-14 CVE-2020-0440 Missing Authorization vulnerability in Google Android 11.0
In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-12-14 CVE-2020-0099 Insecure Default Initialization of Resource vulnerability in Google Android
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value.
local
low complexity
google CWE-1188
7.8
2020-12-10 CVE-2020-26269 Out-of-bounds Read vulnerability in Google Tensorflow 2.4.0
In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an access out of bounds of the array holding the directories.
network
low complexity
google CWE-125
7.5
2020-12-10 CVE-2020-26267 Out-of-bounds Read vulnerability in Google Tensorflow
In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes.
local
low complexity
google CWE-125
7.8
2020-11-10 CVE-2020-0451 Out-of-bounds Write vulnerability in Google Android
In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow.
network
low complexity
google CWE-787
8.8
2020-11-10 CVE-2020-0449 Use After Free vulnerability in Google Android
In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free.
network
low complexity
google CWE-416
8.8
2020-11-10 CVE-2020-0442 Improper Input Validation vulnerability in Google Android
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation.
network
low complexity
google CWE-20
7.5