Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0355 Out-of-bounds Read vulnerability in Google Android 11.0
In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2020-09-17 CVE-2020-0353 Allocation of Resources Without Limits or Throttling vulnerability in Google Android 11.0
In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check.
network
low complexity
google CWE-770
6.5
2020-09-17 CVE-2020-0352 SQL Injection vulnerability in Google Android 11.0
In MediaProvider, there is a possible permissions bypass due to SQL injection.
local
low complexity
google CWE-89
5.5
2020-09-17 CVE-2020-0351 Improper Input Validation vulnerability in Google Android 11.0
In libstagefright, there is possible CPU exhaustion due to improper input validation.
network
low complexity
google CWE-20
6.5
2020-09-17 CVE-2020-0344 SQL Injection vulnerability in Google Android 11.0
In MediaProvider, there is a possible permissions bypass due to SQL injection.
local
low complexity
google CWE-89
5.5
2020-09-17 CVE-2020-0343 Missing Authorization vulnerability in Google Android 11.0
In NetworkStatsService, there is a possible access to protected data due to a missing permission check.
local
low complexity
google CWE-862
5.5
2020-09-17 CVE-2020-0340 Use of Uninitialized Resource vulnerability in Google Android 11.0
In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data.
network
low complexity
google CWE-908
6.5
2020-09-17 CVE-2020-0338 Unspecified vulnerability in Google Android 10.0/9.0
In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass.
local
low complexity
google
5.0
2020-09-17 CVE-2020-0337 Unspecified vulnerability in Google Android 11.0
In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0336 Type Confusion vulnerability in Google Android 11.0
In SurfaceFlinger, there is possible memory corruption due to type confusion.
local
low complexity
google CWE-843
6.7