cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 153 of 339
CVE-2016-3864P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3864 [HIGH] CWE-264 CVE-2016-3864: The Qualcomm radio interface layer in Android before 2016-09-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus The Qualcomm radio interface layer in Android before 2016-09-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28823714 and Qualcomm internal bug CR913117.
nvd
CVE-2015-8937P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2015-8937 [HIGH] CWE-19 CVE-2015-8937: drivers/char/diag/diagchar_core.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 drivers/char/diag/diagchar_core.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 6, and 7 (2013) devices mishandles a socket process, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28803962 and Qualcomm internal bug CR770548.
nvd
CVE-2014-9876P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9876 [HIGH] CWE-189 CVE-2014-9876: drivers/char/diag/diagfwd.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, drivers/char/diag/diagfwd.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices mishandles certain integer values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28767796 and Qualcomm internal bug CR483408.
nvd
CVE-2017-0814P4HIGHCVSS 7.5v4.0v4.0.1+28 more2017-10-04
CVE-2017-0814 [HIGH] CWE-200 CVE-2017-0814: An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Vers An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800140.
nvd
CVE-2014-9880P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9880 [HIGH] CWE-264 CVE-2014-9880: drivers/video/msm/vidc/common/enc/venc.c in the Qualcomm components in Android before 2016-08-05 on drivers/video/msm/vidc/common/enc/venc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not validate VEN_IOCTL_GET_SEQUENCE_HDR ioctl calls, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769352 and Qualcomm internal bug CR556356.
nvd
CVE-2014-9877P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9877 [HIGH] CWE-19 CVE-2014-9877: drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in An drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices mishandles a user-space pointer, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28768281 and Qualcomm internal bug CR547231.
nvd
CVE-2014-9885P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9885 [HIGH] CWE-264 CVE-2014-9885: Format string vulnerability in drivers/thermal/qpnp-adc-tm.c in the Qualcomm components in Android b Format string vulnerability in drivers/thermal/qpnp-adc-tm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application that provides format string specifiers in a name, aka Android internal bug 28769959 and Qualcomm internal bug CR562261.
nvd
CVE-2014-9884P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9884 [HIGH] CWE-20 CVE-2014-9884: drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (201 drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain pointers, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769920 and Qualcomm internal bug CR580740.
nvd
CVE-2016-3758P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-3758 [HIGH] CWE-119 CVE-2016-3758: Multiple buffer overflows in libdex/OptInvocation.cpp in DexClassLoader in Android 4.x before 4.4.4, Multiple buffer overflows in libdex/OptInvocation.cpp in DexClassLoader in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides a long filename, aka internal bug 27840771.
nvd
CVE-2016-3939P4HIGHCVSS 7.8v7.02016-10-10
CVE-2016-3939 [HIGH] CWE-264 CVE-2016-3939: drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nex drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30874196 and Qualcomm internal bug CR 1001224.
nvd
CVE-2016-3792P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2016-3792 [HIGH] CWE-264 CVE-2016-3792: CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-07-05 on Nexus 7 CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-07-05 on Nexus 7 (2013) devices mishandles userspace data copying, which allows attackers to gain privileges via a crafted application, aka Android internal bug 27725204 and Qualcomm internal bug CR561022.
nvd
CVE-2016-2478P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2478 [HIGH] CWE-20 CVE-2016-2478: mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x b mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27475409.
nvd
CVE-2016-2492P4HIGHCVSS 7.8v6.0v6.0.12016-06-13
CVE-2016-2492 [HIGH] CWE-264 CVE-2016-2492: The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows atta The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410.
nvd
CVE-2016-3932P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3932 [HIGH] CWE-264 CVE-2016-3932: mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted applicati mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870.
nvd
CVE-2016-2430P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2430 [HIGH] CWE-264 CVE-2016-2430: libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x befor libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to gain privileges via an application containing a crafted symbol name, aka internal bug 27299236.
nvd
CVE-2017-8247P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-8247 [HIGH] CWE-400 CVE-2017-8247: In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more tha In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would lead to get_pid being called more than once, however put_pid being called only once in function "msm_close".
nvd
CVE-2017-8250P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-8250 [HIGH] CWE-190 CVE-2017-8250: In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled vari In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocated) may occur when they are too large or negative.
nvd
CVE-2016-2432P4HIGHCVSS 7.8≤ 6.0.12016-05-09
CVE-2016-2432 [HIGH] CWE-264 CVE-2016-2432: The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices all The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059.
nvd
CVE-2016-3940P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-3940 [HIGH] CWE-264 CVE-2016-3940: The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 6P and Android One devices al The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 6P and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 30141991.
nvd
CVE-2016-3762P4HIGHCVSS 7.8v5.0v5.0.1+4 more2016-07-11
CVE-2016-3762 [HIGH] CWE-264 CVE-2016-3762: The sockets subsystem in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 a The sockets subsystem in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application that uses (1) the AF_MSM_IPC socket class or (2) another socket class that is unrecognized by SELinux, aka internal bug 28612709.
nvd
Google Android vulnerabilities | cvebase