Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0366 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 11.0
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability.
local
low complexity
google CWE-1021
7.8
2020-09-17 CVE-2020-0360 Unspecified vulnerability in Google Android 11.0
In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent.
local
low complexity
google
7.8
2020-09-17 CVE-2020-0357 Improper Locking vulnerability in Google Android 11.0
In SurfaceFlinger, there is a possible use-after-free due to improper locking.
local
low complexity
google CWE-667
7.8
2020-09-17 CVE-2020-0346 Integer Overflow or Wraparound vulnerability in Google Android 11.0
In Mediaserver, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2020-09-17 CVE-2020-0345 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 11.0
In DocumentsUI, there is a possible permission bypass due to a confused deputy.
local
low complexity
google CWE-610
7.8
2020-09-17 CVE-2020-0341 Missing Authorization vulnerability in Google Android 11.0
In DisplayManager, there is a possible permission bypass due to a missing permission check.
local
low complexity
google CWE-862
7.8
2020-09-17 CVE-2020-0321 Use of Uninitialized Resource vulnerability in Google Android 11.0
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data.
network
low complexity
google CWE-908
8.8
2020-09-17 CVE-2020-0306 Unspecified vulnerability in Google Android 11.0
In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation.
local
low complexity
google
7.8
2020-09-17 CVE-2020-0303 Improper Locking vulnerability in Google Android 11.0
In the Media extractor, there is a possible use after free due to improper locking.
network
low complexity
google CWE-667
8.8
2020-09-17 CVE-2020-0277 Missing Authorization vulnerability in Google Android 11.0
In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check.
local
low complexity
google CWE-862
7.8