Vulnerabilidades em Google Inc.

960 resultados
Análise Vexday

Com 960 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o perfil de exploração ativa do Google Inc. está abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques em curso. Apesar da ausência de severidades críticas e de novas vulnerabilidades nos últimos 90 dias, há 16 CVEs com prova de conceito pública disponível, o que representa um vetor de risco concreto para equipes que ainda não aplicaram as correções correspondentes. A falha mais recorrente é CWE-269 (gerenciamento inadequado de privilégios), padrão que tipicamente favorece escalonamento de privilégios e movimentação lateral em ambientes comprometidos. A CVE mais perigosa atualmente rastreada é CVE-2017-0561, com EPSS de 0,30, indicando probabilidade não negligenciável de exploração e justificando atenção prioritária mesmo tratando-se de uma vulnerabilidade mais antiga.

CVE-2017-0561A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the conEPSS 24.0%CVE-2017-13156An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. EPSS 20.8%CVE-2017-0781A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7EPSS 20.1%CVE-2016-10277An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code withEPSS 16.7%CVE-2017-0569An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code wiEPSS 13.4%CVE-2017-0541A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corrEPSS 12.0%CVE-2017-0785A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, EPSS 9.0%CVE-2016-6707An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malEPSS 8.1%CVE-2017-13208In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This EPSS 7.9%CVE-2017-13262In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remEPSS 6.9%CVE-2017-13260In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatioEPSS 6.3%CVE-2017-13261In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to reEPSS 6.2%CVE-2017-13258In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatioEPSS 6.2%CVE-2017-0540A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corrEPSS 5.9%CVE-2016-6772An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of EPSS 5.0%CVE-2016-6754A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable aEPSS 4.9%CVE-2017-0411An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within thEPSS 4.9%CVE-2017-13253In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locaEPSS 4.7%CVE-2017-0412An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within thEPSS 4.6%CVE-2017-0663A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within thEPSS 4.4%