Vulnerabilities in Google Inc.

960 results
Vexday analysis

Com 960 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o perfil de exploração ativa do Google Inc. está abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques em curso. Apesar da ausência de severidades críticas e de novas vulnerabilidades nos últimos 90 dias, há 16 CVEs com prova de conceito pública disponível, o que representa um vetor de risco concreto para equipes que ainda não aplicaram as correções correspondentes. A falha mais recorrente é CWE-269 (gerenciamento inadequado de privilégios), padrão que tipicamente favorece escalonamento de privilégios e movimentação lateral em ambientes comprometidos. A CVE mais perigosa atualmente rastreada é CVE-2017-0561, com EPSS de 0,30, indicando probabilidade não negligenciável de exploração e justificando atenção prioritária mesmo tratando-se de uma vulnerabilidade mais antiga.

CVE-2016-8429—An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2017-13284—In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This EPSS 1.6%CVE-2017-13292—In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote coEPSS 1.6%CVE-2016-8426—An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-8427—An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-8428—An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2017-13267—In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote esEPSS 1.6%CVE-2016-8425—An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-6760—An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-8479—An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code withEPSS 1.6%CVE-2016-6761—An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-6759—An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-6758—An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code withinEPSS 1.6%CVE-2016-8465—An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code wiEPSS 1.6%CVE-2016-8398—Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: AndEPSS 1.6%CVE-2016-8437—Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. VersionEPSS 1.6%CVE-2017-0422—A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hEPSS 1.6%CVE-2017-13285—In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer. This couEPSS 1.6%CVE-2017-0678—A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.EPSS 1.6%CVE-2017-0700—A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.EPSS 1.6%