Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0384 Out-of-bounds Write vulnerability in Google Android
In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
5.5
2020-09-17 CVE-2020-0383 Out-of-bounds Write vulnerability in Google Android
In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
5.5
2020-09-17 CVE-2020-0379 Unspecified vulnerability in Google Android
In the Bluetooth service, there is a possible spoofing attack due to a logic error.
low complexity
google
5.7
2020-09-15 CVE-2020-8927 Classic Buffer Overflow vulnerability in multiple products
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.
6.5
2020-09-11 CVE-2020-25280 Unspecified vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software.
low complexity
google
6.8
2020-08-31 CVE-2020-25048 Missing Authentication for Critical Function vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software.
low complexity
google CWE-306
4.6
2020-08-31 CVE-2020-25047 Unspecified vulnerability in Google Android 10.0/9.0
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software.
local
low complexity
google
5.5
2020-08-31 CVE-2020-25046 Information Exposure Through Log Files vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
local
low complexity
google CWE-532
5.5
2020-08-12 CVE-2020-8905 Classic Buffer Overflow vulnerability in Google Asylo
A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to.
network
low complexity
google CWE-120
6.5
2020-08-11 CVE-2020-0258 Incomplete Cleanup vulnerability in Google Android 10.0
In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup.
local
low complexity
google CWE-459
5.5