Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0279 Out-of-bounds Read vulnerability in Google Android 11.0
In the AAC parser, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2020-09-17 CVE-2020-0274 Unspecified vulnerability in Google Android 11.0
In the OMX parser, there is a possible information disclosure due to a returned raw pointer.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0270 Out-of-bounds Read vulnerability in Google Android 11.0
In tremolo, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2020-09-17 CVE-2020-0125 Out-of-bounds Read vulnerability in Google Android 11.0
In mediadrm, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-09-17 CVE-2020-0431 Out-of-bounds Write vulnerability in multiple products
In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google opensuse CWE-787
6.7
2020-09-17 CVE-2020-0429 Use After Free vulnerability in Google Android
In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free.
local
low complexity
google CWE-416
6.7
2020-09-17 CVE-2020-0428 Use After Free vulnerability in Google Android
In CamX code, there is a possible use after free due to a race condition.
local
high complexity
google CWE-416
6.4
2020-09-17 CVE-2020-0427 Use After Free vulnerability in multiple products
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free.
5.5
2020-09-17 CVE-2020-0403 Improper Privilege Management vulnerability in Google Android
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature.
local
low complexity
google CWE-269
6.7
2020-09-17 CVE-2020-0407 Use of Insufficiently Random Values vulnerability in Google Android
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits.
local
low complexity
google CWE-330
4.4