cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 121 of 339
CVE-2017-0450P3HIGHCVSS 7.8≤ 7.1.12017-02-08
CVE-2017-0450 [HIGH] CVE-2017-0450: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.
nvd
CVE-2017-0562P3HIGHCVSS 7.8≤ 7.1.12017-04-07
CVE-2017-0562 [HIGH] CVE-2017-0562: An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local mali An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2017-0422P3HIGHCVSS 7.5v4.0v4.0.1+26 more2017-02-08
CVE-2017-0422 [HIGH] CWE-20 CVE-2017-0422: A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially cr A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32322088.
nvd
CVE-2017-0595P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-05-12
CVE-2017-0595 [HIGH] CVE-2017-0595: An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malici An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2017-0594P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-05-12
CVE-2017-0594 [HIGH] CWE-120 CVE-2017-0594: An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Me An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessibl
nvd
CVE-2015-8967P3HIGHCVSS 7.8≤ 7.02016-12-08
CVE-2015-8967 [HIGH] CWE-264 CVE-2015-8967: arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
nvd
CVE-2017-0384P3HIGHCVSS 7.8v4.0v4.0.1+25 more2017-01-12
CVE-2017-0384 [HIGH] CVE-2017-0384: An elevation of privilege vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audi An elevation of privilege vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a thi
nvd
CVE-2017-0596P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-05-12
CVE-2017-0596 [HIGH] CVE-2017-0596: An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malici An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2017-0410P3HIGHCVSS 7.8v5.0v5.0.1+9 more2017-02-08
CVE-2017-0410 [HIGH] CWE-190 CVE-2017-0410: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd
CVE-2017-0546P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-04-07
CVE-2017-0546 [HIGH] CWE-476 CVE-2017-0546: An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Ve
nvd
CVE-2017-0480P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-03-08
CVE-2017-0480 [HIGH] CVE-2017-0480: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd
CVE-2016-6705P3HIGHCVSS 7.8≥ 5.0, < 5.0.2≥ 5.1, < 5.1.1+2 more2016-11-25
CVE-2016-6705 [HIGH] CWE-264 CVE-2016-6705: An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5 An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated c
nvd
CVE-2016-6740P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6740 [HIGH] CWE-264 CVE-2016-6740: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 c An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30143904. References: Qualcomm QC-CR#1056307.
nvd
CVE-2016-6741P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6741 [HIGH] CWE-264 CVE-2016-6741: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 c An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30559423. References: Qualcomm QC-CR#1060554.
nvd
CVE-2016-6738P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6738 [HIGH] CWE-264 CVE-2016-6738: An elevation of privilege vulnerability in the Qualcomm crypto engine driver in Android before 2016- An elevation of privilege vulnerability in the Qualcomm crypto engine driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30034511. References: Qualcomm QC-CR#105053
nvd
CVE-2017-0597P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-05-12
CVE-2017-0597 [HIGH] CWE-190 CVE-2017-0597: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0479P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-03-08
CVE-2017-0479 [HIGH] CVE-2017-0479: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd
CVE-2016-6739P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6739 [HIGH] CWE-264 CVE-2016-6739: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 c An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30074605. References: Qualcomm QC-CR#1049826.
nvd
CVE-2016-6737P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6737 [HIGH] CWE-264 CVE-2016-6737: An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 cou An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair
nvd
CVE-2016-3904P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-3904 [HIGH] CWE-264 CVE-2016-3904: An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 coul An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30311977. References: Qualcomm QC-CR#1050455.
nvd
Google Android vulnerabilities | cvebase