Vulnerabilidades em google
7.003 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2018-9412MEDIUMIn removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial ofEPSS 0.1%CVE-2024-40669HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2018-9369HIGHIn bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilEPSS 0.1%CVE-2024-40670HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2025-48628HIGHIn validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could leadEPSS 0.1%CVE-2024-29780MEDIUMIn hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitiEPSS 0.1%CVE-2025-48607MEDIUMIn multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to locaEPSS 0.1%CVE-2026-0087HIGHIn approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic EPSS 0.1%CVE-2024-32907HIGHIn memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of priEPSS 0.1%CVE-2026-0016LOWIn updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a peEPSS 0.1%CVE-2025-48632HIGHIn setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated EPSS 0.1%CVE-2023-40113MEDIUMIn multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could leadEPSS 0.1%CVE-2024-47032HIGHIn construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead toEPSS 0.1%CVE-2024-40656MEDIUMIn handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused EPSS 0.1%CVE-2025-48629HIGHIn findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to anEPSS 0.1%CVE-2026-0107HIGHIn gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to locEPSS 0.1%CVE-2018-9449MEDIUMIn process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could leadEPSS 0.1%CVE-2025-26429MEDIUMIn collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to locEPSS 0.1%CVE-2025-22420HIGHIn multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local eEPSS 0.1%CVE-2025-22439HIGHIn onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing perEPSS 0.1%