Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-10-14 CVE-2020-0419 Missing Authorization vulnerability in Google Android
In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check.
local
low complexity
google CWE-862
5.5
2020-10-14 CVE-2020-0415 Unspecified vulnerability in Google Android
In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-10-14 CVE-2020-0414 Improper Initialization vulnerability in Google Android 10.0/11.0
In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due to a permissions bypass.
network
low complexity
google CWE-665
6.5
2020-10-14 CVE-2020-0411 Use of Uninitialized Resource vulnerability in Google Android 10.0/11.0
In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data.
network
low complexity
google CWE-908
6.5
2020-10-14 CVE-2020-0410 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error.
local
low complexity
google CWE-732
5.5
2020-10-14 CVE-2020-0400 Unspecified vulnerability in Google Android 10.0/11.0
In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-10-14 CVE-2020-0398 Unspecified vulnerability in Google Android 10.0/11.0
In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error.
local
low complexity
google
5.5
2020-10-14 CVE-2020-0378 Missing Authorization vulnerability in Google Android 10.0/11.0/9.0
In onWnmFrameReceived of PasspointManager.java, there is a missing permission check.
local
low complexity
google CWE-862
5.5
2020-10-14 CVE-2020-0246 Missing Authorization vulnerability in Google Android 10.0/11.0
In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check.
local
low complexity
google CWE-862
5.5
2020-10-06 CVE-2020-26603 Path Traversal vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
network
low complexity
google CWE-22
5.3