Vulnerabilities > Google > Low

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0389 Incorrect Authorization vulnerability in Google Android 10.0/11.0
In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-863
2.1
2020-09-17 CVE-2020-0390 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
In the app zygote SE Policy, there is a possible permissions bypass.
local
low complexity
google CWE-276
2.1
2020-09-17 CVE-2020-0407 Inadequate Encryption Strength vulnerability in Google Android
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits.
local
low complexity
google CWE-326
2.1
2020-08-31 CVE-2020-25046 Information Exposure Through Log Files vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
local
low complexity
google CWE-532
2.1
2020-08-31 CVE-2020-25047 Unspecified vulnerability in Google Android 10.0/9.0
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software.
local
low complexity
google
2.1
2020-08-31 CVE-2020-25048 Injection vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software.
local
low complexity
google CWE-74
2.1
2020-08-11 CVE-2020-8918 Improper Initialization vulnerability in Google Go-Tpm
An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey.
local
low complexity
google CWE-665
3.6
2020-07-17 CVE-2020-0107 Incorrect Default Permissions vulnerability in Google Android 10.0
In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation.
local
low complexity
google CWE-276
2.1
2020-07-07 CVE-2020-15577 Unspecified vulnerability in Google Android 10.0/9.0
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software.
local
low complexity
google
2.1
2020-07-07 CVE-2020-15578 Incorrect Default Permissions vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
local
low complexity
google CWE-276
2.1