Vulnerabilidades en Google Inc.

960 resultados
Análisis Vexday

Com 960 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o perfil de exploração ativa do Google Inc. está abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques em curso. Apesar da ausência de severidades críticas e de novas vulnerabilidades nos últimos 90 dias, há 16 CVEs com prova de conceito pública disponível, o que representa um vetor de risco concreto para equipes que ainda não aplicaram as correções correspondentes. A falha mais recorrente é CWE-269 (gerenciamento inadequado de privilégios), padrão que tipicamente favorece escalonamento de privilégios e movimentação lateral em ambientes comprometidos. A CVE mais perigosa atualmente rastreada é CVE-2017-0561, com EPSS de 0,30, indicando probabilidade não negligenciável de exploração e justificando atenção prioritária mesmo tratando-se de uma vulnerabilidade mais antiga.

CVE-2017-0480An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the conteEPSS 0.8%CVE-2017-0488A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. EPSS 0.8%CVE-2017-0487A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. EPSS 0.8%CVE-2017-0596An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary codEPSS 0.8%CVE-2017-13209In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller wEPSS 0.8%CVE-2017-0387An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the conteEPSS 0.8%CVE-2016-6705An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 befEPSS 0.8%CVE-2017-0523An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code wiEPSS 0.7%CVE-2016-8485An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-2882EPSS 0.7%CVE-2017-0501An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and EPSS 0.7%CVE-2017-0500An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and EPSS 0.7%CVE-2016-8486An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-2882EPSS 0.7%CVE-2017-0506An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and EPSS 0.7%CVE-2017-0502An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and EPSS 0.7%CVE-2016-6756An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious aEPSS 0.7%CVE-2017-0650An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outsidEPSS 0.7%CVE-2016-6757An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious aEPSS 0.7%CVE-2016-6713A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker EPSS 0.7%CVE-2017-0740A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488.EPSS 0.7%CVE-2017-0713A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7EPSS 0.7%