cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 278 of 339
CVE-2016-3830P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-08-05
CVE-2016-3830 [MEDIUM] CWE-20 CVE-2016-3830: codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x befor codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS data, aka internal bug 29153599.
nvd
CVE-2016-6679P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6679 [MEDIUM] CWE-200 CVE-2016-6679: CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5 CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain sensitive information via a crafted application that makes a setwpaie ioctl call, aka Android internal bug 29915601 and Qualcomm internal bug CR 1000913.
nvd
CVE-2017-0559P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-04-07
CVE-2017-0559 [MEDIUM] CWE-200 CVE-2017-0559: An information disclosure vulnerability in libskia could enable a local malicious application to acc An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33897722.
nvd
CVE-2017-0555P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0555 [MEDIUM] CWE-200 CVE-2017-0555: An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious appl An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33551775.
nvd
CVE-2018-9444P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2018-11-06
CVE-2018-9444 [MEDIUM] CWE-835 CVE-2018-9444: In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite lo In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Androi
nvd
CVE-2017-0556P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0556 [MEDIUM] CWE-200 CVE-2017-0556: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious ap An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093952.
nvd
CVE-2016-3902P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-3902 [MEDIUM] CWE-200 CVE-2016-3902: drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 o drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29953313 and Qualcomm internal bug CR 1044072.
nvd
CVE-2017-0402P4MEDIUMCVSS 5.5≥ 4.0, ≤ 4.4.4≥ 5.0, ≤ 5.0.2+4 more2017-01-12
CVE-2017-0402 [MEDIUM] CWE-200 CVE-2017-0402: An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audi An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.
nvd
CVE-2016-2458P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-05-09
CVE-2016-2458 [MEDIUM] CWE-200 CVE-2016-2458: The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x be The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive information via a crafted application, related to ComposeActivity.java and ComposeActivityEmail.java, aka internal bug 27335139.
nvd
CVE-2016-2425P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-04-18
CVE-2016-2425 [MEDIUM] CWE-200 CVE-2016-2425: mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1. mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 supports file:///data attachments, which allows attackers to obtain sensitive information via a crafted application, aka internal bugs 7154234 and 26989185.
nvd
CVE-2016-3835P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-08-05
CVE-2016-3835 [MEDIUM] CWE-200 CVE-2016-3835: The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 28920116.
nvd
CVE-2014-9894P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9894 [MEDIUM] CWE-200 CVE-2014-9894: drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) dev drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not ensure that certain name strings end in a '\0' character, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28749708 and Qualcomm internal bug CR545736.
nvd
CVE-2017-0400P4MEDIUMCVSS 5.5v4.0v4.0.1+22 more2017-01-12
CVE-2017-0400 [MEDIUM] CWE-200 CVE-2017-0400: An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audi An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.
nvd
CVE-2017-0396P4MEDIUMCVSS 5.5v4.0v4.0.1+25 more2017-01-12
CVE-2017-0396 [MEDIUM] CWE-200 CVE-2017-0396: An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaser An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6
nvd
CVE-2016-3836P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-08-05
CVE-2016-3836 [MEDIUM] CWE-200 CVE-2016-3836: The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08 The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka internal bug 28592402.
nvd
CVE-2016-3860P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-3860 [MEDIUM] CWE-200 CVE-2016-3860: sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29323142 and Qualcomm internal bug CR 1038127.
nvd
CVE-2017-0490P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0490 [MEDIUM] CVE-2017-0490: An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delet An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delete user data. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33178389.
nvd
CVE-2017-0326P4MEDIUMCVSS 5.5v7.1.22017-07-07
CVE-2017-0326 [MEDIUM] CWE-200 CVE-2017-0326: An information disclosure vulnerability in the NVIDIA Video Driver due to an out-of-bounds read func An information disclosure vulnerability in the NVIDIA Video Driver due to an out-of-bounds read function in the Tegra Display Controller driver could result in possible information disclosure. This issue is rated as Moderate. Product: Android. Version: N/A. Android ID: A-33718700. References: N-CVE-2017-0326.
nvd
CVE-2016-2415P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-04-18
CVE-2016-2415 [MEDIUM] CWE-200 CVE-2016-2415: exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Andro exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to obtain sensitive information via a crafted application that triggers a spoofed response to a GET request, aka internal bug 26488455.
nvd
CVE-2017-0708P4MEDIUMCVSS 5.5v7.1.22017-07-06
CVE-2017-0708 [MEDIUM] CWE-200 CVE-2017-0708: A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.
nvd
Google Android vulnerabilities | cvebase