Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-08 CVE-2019-2052 Type Confusion vulnerability in Google Android
In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion.
network
low complexity
google CWE-843
7.5
2019-05-08 CVE-2019-2051 Out-of-bounds Read vulnerability in Google Android
In heap of spaces.h, there is a possible out of bounds read due to improper input validation.
network
low complexity
google CWE-125
7.5
2019-05-08 CVE-2019-2050 Improper Locking vulnerability in Google Android 8.0/8.1/9.0
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking.
local
low complexity
google CWE-667
7.8
2019-05-08 CVE-2019-2049 Use After Free vulnerability in Google Android 9.0
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free.
local
low complexity
google CWE-416
7.8
2019-05-08 CVE-2019-2044 Out-of-bounds Write vulnerability in Google Android
In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check.
network
low complexity
google CWE-787
8.8
2019-05-08 CVE-2019-2043 Insecure Default Initialization of Resource vulnerability in Google Android
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack.
local
low complexity
google CWE-1188
7.3
2019-05-07 CVE-2018-6243 Improper Input Validation vulnerability in Google Android
NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead to Arbitrary Code Execution, Denial of Service or Escalation of Privileges.
local
low complexity
google CWE-20
7.8
2019-04-24 CVE-2018-7577 Improper Input Validation vulnerability in Google Tensorflow
Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a crash or read from other parts of process memory.
network
low complexity
google CWE-20
8.1
2019-04-24 CVE-2018-10055 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Tensorflow
Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 could cause a crash or read from other parts of process memory via a crafted configuration file.
network
low complexity
google CWE-119
8.1
2019-04-23 CVE-2018-8825 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Tensorflow
Google TensorFlow 1.7 and below is affected by: Buffer Overflow.
network
low complexity
google CWE-119
8.8