Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0404 Improper Privilege Management vulnerability in multiple products
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause.
local
low complexity
google oracle CWE-269
5.5
2020-09-17 CVE-2020-0399 Unspecified vulnerability in Google Android
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0397 Unspecified vulnerability in Google Android
In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0396 Unspecified vulnerability in Google Android
In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0395 Unspecified vulnerability in Google Android
In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0393 Out-of-bounds Read vulnerability in Google Android 10.0/9.0
In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2020-09-17 CVE-2020-0390 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
In the app zygote SE Policy, there is a possible permissions bypass.
local
low complexity
google CWE-276
5.5
2020-09-17 CVE-2020-0389 Unspecified vulnerability in Google Android 10.0/11.0
In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google
5.5
2020-09-17 CVE-2020-0386 Insecure Default Initialization of Resource vulnerability in Google Android
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value.
local
low complexity
google CWE-1188
5.5
2020-09-17 CVE-2020-0385 Out-of-bounds Write vulnerability in Google Android
In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
5.5