Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-22 CVE-2020-8903 Incorrect Default Permissions vulnerability in multiple products
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root.
local
low complexity
google opensuse CWE-276
7.8
2020-06-16 CVE-2020-0234 Out-of-bounds Write vulnerability in Google Android
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2020-06-11 CVE-2020-0233 Use After Free vulnerability in Google Android 10.0
In main of main.cpp, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2020-06-11 CVE-2020-0219 NULL Pointer Dereference vulnerability in Google Android 10.0
In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent.
local
low complexity
google CWE-476
7.8
2020-06-11 CVE-2020-0218 Out-of-bounds Write vulnerability in Google Android 10.0
In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition.
local
high complexity
google CWE-787
7.0
2020-06-11 CVE-2020-0216 Integer Overflow or Wraparound vulnerability in Google Android 10.0
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow.
local
low complexity
google CWE-190
7.8
2020-06-11 CVE-2020-0215 Incorrect Default Permissions vulnerability in Google Android
In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass.
local
low complexity
google CWE-276
7.8
2020-06-11 CVE-2020-0214 Out-of-bounds Read vulnerability in Google Android 10.0
In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check.
network
low complexity
google CWE-125
7.5
2020-06-11 CVE-2020-0210 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 10.0
In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy.
local
low complexity
google CWE-610
7.8
2020-06-11 CVE-2020-0209 Incorrect Default Permissions vulnerability in Google Android 10.0
In multiple functions of AccountManager.java, there is a possible permissions bypass.
local
low complexity
google CWE-276
7.8