Vulnerabilities in Google LLC

64 results
Vexday analysis

Com 64 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o perfil de risco deste vendor situa-se abaixo da média geral do catálogo, o que sugere uma superfície de ataque relativamente contida no momento. Das vulnerabilidades registradas, 3 são de severidade crítica e apenas 1 conta com prova de conceito pública, fator que eleva marginalmente o risco de tentativas de exploração oportunistas. A CVE mais perigosa ativa no momento é CVE-2020-8927, com EPSS de 0,0324, indicando probabilidade baixa de exploração em curto prazo, embora sua presença mereça acompanhamento em ambientes que ainda não aplicaram as devidas correções. A predominância de CWE-120 (buffer overflow clássico) como tipo de falha mais recorrente aponta para uma classe de vulnerabilidade que, historicamente, pode resultar em execução de código arbitrário, reforçando a importância de manter ciclos de patching rigorosos mesmo quando a pressão imediata de exploração é baixa.

CVE-2021-22556MEDIUMInteger Overflow in Fuchsia KernelEPSS 0.2%CVE-2020-8944MEDIUMUnchecked buffer overrun in ecall_restoreEPSS 0.2%CVE-2021-22552MEDIUMMemory overread secure enclave in Asylo 0.6.2EPSS 0.2%CVE-2020-8935MEDIUMAn arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to realloEPSS 0.1%CVE-2020-8941MEDIUMUnchecked buffer overrun in enc_untrusted_inet_ptonEPSS 0.1%CVE-2020-8936MEDIUMArbitrary enclave memory overwrite vulnerability in ECall ecall_restoreEPSS 0.1%CVE-2020-8940MEDIUMUnchecked buffer overrun in enc_untrusted_recvmsgEPSS 0.1%CVE-2020-8942MEDIUMUnchecked buffer overrun in enc_untrusted_readEPSS 0.1%CVE-2020-8939MEDIUMOut of Bounds read in AsyloEPSS 0.1%CVE-2021-22572MEDIUMData-transfer-project information disclosure via tmp directoryEPSS 0.1%CVE-2020-8943MEDIUMUnchecked buffer overrun in enc_untrusted_recvfromEPSS 0.1%CVE-2022-25326MEDIUMDenial of Service in fscryptEPSS 0.1%CVE-2020-8938MEDIUMArbitrary enclave memory location write from untrusted environmentEPSS 0.1%CVE-2020-8937MEDIUMArbitrary enclave memory location write from untrusted environmentEPSS 0.1%CVE-2022-3421MEDIUMPrivilege escalation in Google Drive for Desktop on MacOSEPSS 0.1%CVE-2021-22549MEDIUMArbitrary enclave memory overwrite vulnerability in Asylo TrustedPrimitives::UntrustedCallEPSS 0.1%CVE-2021-22548MEDIUMArbitrary enclave memory overread vulnerability in Asylo TrustedPrimitives::UntrustedCallEPSS 0.1%CVE-2022-0882MEDIUMIllegal access to Kernel log in Fuchsia EPSS 0.1%CVE-2022-25327MEDIUMLocal Denial of Service in fscrypt PAM moduleEPSS 0.1%CVE-2022-2390MEDIUMMutable pending intent in Google Play services SDKEPSS 0.1%