Vulnerabilidades em Google Inc.

960 resultados
Análise Vexday

Com 960 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o perfil de exploração ativa do Google Inc. está abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques em curso. Apesar da ausência de severidades críticas e de novas vulnerabilidades nos últimos 90 dias, há 16 CVEs com prova de conceito pública disponível, o que representa um vetor de risco concreto para equipes que ainda não aplicaram as correções correspondentes. A falha mais recorrente é CWE-269 (gerenciamento inadequado de privilégios), padrão que tipicamente favorece escalonamento de privilégios e movimentação lateral em ambientes comprometidos. A CVE mais perigosa atualmente rastreada é CVE-2017-0561, com EPSS de 0,30, indicando probabilidade não negligenciável de exploração e justificando atenção prioritária mesmo tratando-se de uma vulnerabilidade mais antiga.

CVE-2017-0522An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application to execute arbitrary code within the coEPSS 0.7%CVE-2017-13276In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a missing bounds check. This could lead tEPSS 0.7%CVE-2016-8436An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code wiEPSS 0.7%CVE-2018-9555In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalatiEPSS 0.7%CVE-2017-0390A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to use a specially crafted file to cause aEPSS 0.7%CVE-2018-9508In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could leadEPSS 0.7%CVE-2017-0392A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially craftEPSS 0.7%CVE-2018-9506In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote informationEPSS 0.7%CVE-2016-8414An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious applicationEPSS 0.7%CVE-2017-13204An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. AnEPSS 0.7%CVE-2016-6733An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to EPSS 0.7%CVE-2016-6730An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to EPSS 0.7%CVE-2016-6731An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to EPSS 0.7%CVE-2016-6732An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to EPSS 0.7%CVE-2016-10275An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code withEPSS 0.7%CVE-2017-13222An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-38159576.EPSS 0.7%CVE-2017-0389A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a devicEPSS 0.7%CVE-2017-0420An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that EPSS 0.7%CVE-2017-0413An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections EPSS 0.7%CVE-2017-13255In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds check. This could lead to remote code eEPSS 0.7%