Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2020-05-14 CVE-2020-0094 Out-of-bounds Write vulnerability in Google Android 10.0/9.0
In setImageHeight and setImageWidth of ExifUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8
2020-05-14 CVE-2020-0024 Incorrect Default Permissions vulnerability in Google Android
In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass.
local
low complexity
google CWE-276
7.8
2020-05-11 CVE-2020-12754 Unspecified vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software.
local
low complexity
google
7.8
2020-05-11 CVE-2020-12752 Improper Restriction of Excessive Authentication Attempts vulnerability in Google Android 10.0/9.0
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software.
network
low complexity
google CWE-307
7.5
2020-05-11 CVE-2020-12751 Out-of-bounds Write vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software.
local
low complexity
google CWE-787
7.8
2020-05-11 CVE-2020-12750 Unspecified vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) software.
network
low complexity
google
7.5
2020-05-11 CVE-2020-12749 Classic Buffer Overflow vulnerability in Google Android 9.0
An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software.
local
low complexity
google CWE-120
7.8
2020-05-11 CVE-2020-12745 Missing Authorization vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) software.
network
low complexity
google CWE-862
7.5
2020-04-21 CVE-2020-8895 Untrusted Search Path vulnerability in Google Earth
Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system.
local
low complexity
google CWE-426
7.8
2020-04-17 CVE-2020-0082 Deserialization of Untrusted Data vulnerability in Google Android 10.0
In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization.
local
low complexity
google CWE-502
7.8