Vulnerabilidades en Google Inc.

960 resultados
Análisis Vexday

Com 960 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o perfil de exploração ativa do Google Inc. está abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques em curso. Apesar da ausência de severidades críticas e de novas vulnerabilidades nos últimos 90 dias, há 16 CVEs com prova de conceito pública disponível, o que representa um vetor de risco concreto para equipes que ainda não aplicaram as correções correspondentes. A falha mais recorrente é CWE-269 (gerenciamento inadequado de privilégios), padrão que tipicamente favorece escalonamento de privilégios e movimentação lateral em ambientes comprometidos. A CVE mais perigosa atualmente rastreada é CVE-2017-0561, com EPSS de 0,30, indicando probabilidade não negligenciável de exploração e justificando atenção prioritária mesmo tratando-se de uma vulnerabilidade mais antiga.

CVE-2017-0405A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause memory corruption dEPSS 1.8%CVE-2017-13194A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1.EPSS 1.8%CVE-2016-10285An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code wiEPSS 1.8%CVE-2016-10290An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious application to execute arbitraryEPSS 1.8%CVE-2017-0521An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code wEPSS 1.8%CVE-2016-6775An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.8%CVE-2016-6789An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrEPSS 1.8%CVE-2016-6777An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.8%CVE-2016-6776An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 1.8%CVE-2017-13160A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-37EPSS 1.8%CVE-2017-13229A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-6EPSS 1.8%CVE-2017-13266In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote coEPSS 1.8%CVE-2017-13272In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation ofEPSS 1.8%CVE-2017-13281In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check. This could lead toEPSS 1.8%CVE-2017-0518An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbiEPSS 1.8%CVE-2017-0516An elevation of privilege vulnerability in the Qualcomm input hardware driver could enable a local malicious application to execute arbitrarEPSS 1.8%CVE-2017-13195In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes EPSS 1.7%CVE-2017-13192In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an inEPSS 1.7%CVE-2017-13191In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could lead to a remote deEPSS 1.7%CVE-2017-0855In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memoryEPSS 1.7%