Vulnerabilidades en Google Inc.

960 resultados
Análisis Vexday

Com 960 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o perfil de exploração ativa do Google Inc. está abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques em curso. Apesar da ausência de severidades críticas e de novas vulnerabilidades nos últimos 90 dias, há 16 CVEs com prova de conceito pública disponível, o que representa um vetor de risco concreto para equipes que ainda não aplicaram as correções correspondentes. A falha mais recorrente é CWE-269 (gerenciamento inadequado de privilégios), padrão que tipicamente favorece escalonamento de privilégios e movimentação lateral em ambientes comprometidos. A CVE mais perigosa atualmente rastreada é CVE-2017-0561, com EPSS de 0,30, indicando probabilidade não negligenciável de exploração e justificando atenção prioritária mesmo tratando-se de uma vulnerabilidade mais antiga.

CVE-2016-8435An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.2%CVE-2017-0832A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, EPSS 1.2%CVE-2016-8463A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause aEPSS 1.2%CVE-2016-8434An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code withEPSS 1.2%CVE-2017-0409A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code inEPSS 1.2%CVE-2016-6755An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code wEPSS 1.2%CVE-2016-6791An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code wiEPSS 1.2%CVE-2016-8392An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code wiEPSS 1.2%CVE-2018-9502In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remoEPSS 1.2%CVE-2016-8391An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code wiEPSS 1.2%CVE-2017-0814An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android IDEPSS 1.2%CVE-2018-9527In vorbis_book_decodev_set of codebook.c there is a possible out of bounds write due to missing bounds check. This could lead to remote codeEPSS 1.2%CVE-2017-13176In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation ofEPSS 1.2%CVE-2016-10289An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious application to execute arbitrary code wEPSS 1.2%CVE-2017-0386An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within theEPSS 1.1%CVE-2017-0806An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7EPSS 1.1%CVE-2016-8397An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its EPSS 1.1%CVE-2018-9565In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information discEPSS 1.1%CVE-2017-0444An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code witEPSS 1.1%CVE-2018-9571In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This coEPSS 1.1%