cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 143 of 339
CVE-2014-9783P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9783 [HIGH] CWE-264 CVE-2014-9783: drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm components in Android befo drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices does not validate certain values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28441831 and Qualcomm internal bug CR511382.
nvd
CVE-2016-3903P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3903 [HIGH] CWE-264 CVE-2016-3903: drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm camera driver in Android drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm camera driver in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29513227 and Qualcomm internal bug CR 1040857.
nvd
CVE-2016-3931P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3931 [HIGH] CWE-264 CVE-2016-3931: drivers/misc/qseecom.c in the Qualcomm QSEE Communicator driver in Android before 2016-10-05 on Nexu drivers/misc/qseecom.c in the Qualcomm QSEE Communicator driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29157595 and Qualcomm internal bug CR 1036418.
nvd
CVE-2014-9777P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9777 [HIGH] CWE-119 CVE-2014-9777: The vid_dec_set_meta_buffers function in drivers/video/msm/vidc/common/dec/vdec.c in the Qualcomm co The vid_dec_set_meta_buffers function in drivers/video/msm/vidc/common/dec/vdec.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate the number of buffers, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28598501 and Qualcomm internal bug CR563654.
nvd
CVE-2014-9782P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9782 [HIGH] CWE-264 CVE-2014-9782: drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in An drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate direction and step parameters, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28431531 and Qualcomm internal bug CR511349.
nvd
CVE-2014-9778P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9778 [HIGH] CWE-119 CVE-2014-9778: The vid_dec_set_h264_mv_buffers function in drivers/video/msm/vidc/common/dec/vdec.c in the Qualcomm The vid_dec_set_h264_mv_buffers function in drivers/video/msm/vidc/common/dec/vdec.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate the number of buffers, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28598515 and Qualcomm internal bug CR563694.
nvd
CVE-2014-9869P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9869 [HIGH] CWE-264 CVE-2014-9869: drivers/media/platform/msm/camera_v2/isp/msm_isp_stats_util.c in the Qualcomm components in Android drivers/media/platform/msm/camera_v2/isp/msm_isp_stats_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain index values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28749728 and Qualcomm internal bug CR514711.
nvd
CVE-2014-9796P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9796 [HIGH] CWE-264 CVE-2014-9796: app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) de app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate the page size in the kernel header, which allows attackers to bypass intended access restrictions via a crafted boot image, aka Android internal bug 28820722 and Qualcomm internal bug CR684756.
nvd
CVE-2015-8892P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2015-8892 [HIGH] CWE-264 CVE-2015-8892: platform/msm_shared/boot_verifier.c in the Qualcomm components in Android before 2016-07-05 on Nexus platform/msm_shared/boot_verifier.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to bypass intended access restrictions via a digest with trailing data, aka Android internal bug 28822807 and Qualcomm internal bug CR902998.
nvd
CVE-2014-9800P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9800 [HIGH] CWE-189 CVE-2014-9800: Integer overflow in lib/heap/heap.c in the Qualcomm components in Android before 2016-07-05 on Nexus Integer overflow in lib/heap/heap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28822150 and Qualcomm internal bug CR692478.
nvd
CVE-2015-8940P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2015-8940 [HIGH] CWE-264 CVE-2015-8940: Integer overflow in sound/soc/msm/qdsp6v2/q6lsm.c in the Qualcomm components in Android before 2016- Integer overflow in sound/soc/msm/qdsp6v2/q6lsm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28813987 and Qualcomm internal bug CR792367.
nvd
CVE-2014-9866P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9866 [HIGH] CWE-20 CVE-2014-9866: drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm components in Android be drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate a certain parameter, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747684 and Qualcomm internal bug CR511358.
nvd
CVE-2016-3935P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3935 [HIGH] CWE-190 CVE-2016-3935: Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine drive Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999665 and Qualcomm internal bug CR 1046507.
nvd
CVE-2015-8888P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2015-8888 [HIGH] CWE-189 CVE-2015-8888: Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nex Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to bypass intended access restrictions via a crafted block count and block size of a sparse header, aka Android internal bug 28822465 and Qualcomm internal bug CR813933.
nvd
CVE-2016-3938P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3938 [HIGH] CWE-264 CVE-2016-3938: drivers/video/msm/mdss/mdss_mdp_overlay.c in the Qualcomm video driver in Android before 2016-10-05 drivers/video/msm/mdss/mdss_mdp_overlay.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30019716 and Qualcomm internal bug CR 1049232.
nvd
CVE-2015-8942P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2015-8942 [HIGH] CWE-264 CVE-2015-8942: drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android befor drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices does not validate the stream state, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28814652 and Qualcomm internal bug CR803246.
nvd
CVE-2016-3916P4HIGHCVSS 7.8v4.0v4.0.1+21 more2016-10-10
CVE-2016-3916 [HIGH] CWE-119 CVE-2016-3916: camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30741779.
nvd
CVE-2016-3915P4HIGHCVSS 7.8v4.0v4.0.1+21 more2016-10-10
CVE-2016-3915 [HIGH] CWE-264 CVE-2016-3915: camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30591838.
nvd
CVE-2016-3921P4HIGHCVSS 7.8v4.0v4.0.1+21 more2016-10-10
CVE-2016-3921 [HIGH] CWE-264 CVE-2016-3921: libsysutils/src/FrameworkListener.cpp in Framework Listener in Android 4.x before 4.4.4, 5.0.x befor libsysutils/src/FrameworkListener.cpp in Framework Listener in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 29831647.
nvd
CVE-2016-3858P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3858 [HIGH] CWE-119 CVE-2016-3858: Buffer overflow in drivers/soc/qcom/subsystem_restart.c in the Qualcomm subsystem driver in Android Buffer overflow in drivers/soc/qcom/subsystem_restart.c in the Qualcomm subsystem driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application that provides a long string, aka Android internal bug 28675151 and Qualcomm internal bug CR1022641.
nvd
Google Android vulnerabilities | cvebase