cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 152 of 339
CVE-2014-9801P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9801 [HIGH] CWE-189 CVE-2014-9801: Multiple integer overflows in lib/libfdt/fdt_rw.c in the Qualcomm components in Android before 2016- Multiple integer overflows in lib/libfdt/fdt_rw.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28822060 and Qualcomm internal bug CR705078.
nvd
CVE-2014-9793P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9793 [HIGH] CWE-254 CVE-2014-9793: platform/msm_shared/mmc.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) platform/msm_shared/mmc.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices mishandles the power-on write-protect feature, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28821253 and Qualcomm internal bug CR580567.
nvd
CVE-2014-9864P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9864 [HIGH] CWE-20 CVE-2014-9864: drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (201 drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate ioctl calls, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747998 and Qualcomm internal bug CR561841.
nvd
CVE-2014-9867P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9867 [HIGH] CWE-264 CVE-2014-9867: drivers/media/platform/msm/camera_v2/isp/msm_isp_axi_util.c in the Qualcomm components in Android be drivers/media/platform/msm/camera_v2/isp/msm_isp_axi_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate the number of streams, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28749629 and Qualcomm internal bug CR514702.
nvd
CVE-2015-8938P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2015-8938 [HIGH] CWE-264 CVE-2015-8938: The MSM camera driver in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices doe The MSM camera driver in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices does not validate input parameters, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28804030 and Qualcomm internal bug CR766022.
nvd
CVE-2015-8891P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2015-8891 [HIGH] CWE-189 CVE-2015-8891: Multiple integer overflows in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07 Multiple integer overflows in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to bypass intended access restrictions via a crafted image, aka Android internal bug 28842418 and Qualcomm internal bug CR813930.
nvd
CVE-2014-9887P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9887 [HIGH] CWE-264 CVE-2014-9887: drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (201 drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain length values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28804057 and Qualcomm internal bug CR636633.
nvd
CVE-2014-9890P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9890 [HIGH] CWE-264 CVE-2014-9890: Off-by-one error in drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm compon Off-by-one error in drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application that sends an I2C command, aka Android internal bug 28770207 and Qualcomm internal bug CR529177.
nvd
CVE-2015-8939P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2015-8939 [HIGH] CWE-264 CVE-2015-8939: drivers/video/msm/mdp4_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (20 drivers/video/msm/mdp4_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not validate r stages, g stages, or b stages data, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28398884 and Qualcomm internal bug CR779021.
nvd
CVE-2017-11041P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-11041 [HIGH] CVE-2017-11041: In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.
nvd
CVE-2016-0820P4HIGHCVSS 7.8v6.0.12016-03-12
CVE-2016-0820 [HIGH] CWE-264 CVE-2016-0820: The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privile The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 26267358.
nvd
CVE-2016-3752P4HIGHCVSS 7.8v6.0v6.0.12016-07-11
CVE-2016-3752 [HIGH] CWE-19 CVE-2016-3752: internal/app/ChooserActivity.java in the ChooserTarget service in Android 6.x before 2016-07-01 mish internal/app/ChooserActivity.java in the ChooserTarget service in Android 6.x before 2016-07-01 mishandles target security checks, which allows attackers to gain privileges via a crafted application, aka internal bug 28384423.
nvd
CVE-2016-3937P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3937 [HIGH] CWE-20 CVE-2016-3937: The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a cra The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30030994 and MediaTek internal bug ALPS02834874.
nvd
CVE-2016-3936P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3936 [HIGH] CWE-20 CVE-2016-3936: The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a cra The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019037 and MediaTek internal bug ALPS02829568.
nvd
CVE-2016-3928P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3928 [HIGH] CWE-264 CVE-2016-3928: The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a cra The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019362 and MediaTek internal bug ALPS02829384.
nvd
CVE-2016-2487P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2487 [HIGH] CWE-20 CVE-2016-2487: libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, a libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27833616.
nvd
CVE-2014-9881P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9881 [HIGH] CWE-264 CVE-2014-9881: drivers/media/radio/radio-iris.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 drivers/media/radio/radio-iris.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices uses an incorrect integer data type, which allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application, aka Android internal bug 28769368 and Qualcomm internal bug CR539008.
nvd
CVE-2016-2502P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2016-2502 [HIGH] CWE-264 CVE-2016-2502: drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android before 2016-07-05 on Nexus 5X an drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a large size in a GSER_IOCTL ioctl call, aka Android internal bug 27657963 and Qualcomm internal bug CR997044.
nvd
CVE-2016-2477P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2477 [HIGH] CWE-20 CVE-2016-2477: mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x b mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27251096.
nvd
CVE-2015-6638P4HIGHCVSS 7.8v5.0v5.1.1+2 more2016-01-06
CVE-2015-6638 [HIGH] CWE-264 CVE-2015-6638: The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 all The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.
nvd
Google Android vulnerabilities | cvebase