cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 294 of 339
CVE-2017-0486P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0486 [MEDIUM] CVE-2017-0486: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33621215.
nvd
CVE-2017-0483P4MEDIUMCVSS 5.5v5.0v5.0.1+9 more2017-03-08
CVE-2017-0483 [MEDIUM] CWE-20 CVE-2017-0483: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33137046.
nvd
CVE-2017-0485P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0485 [MEDIUM] CVE-2017-0485: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33387820.
nvd
CVE-2017-0484P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0484 [MEDIUM] CWE-20 CVE-2017-0484: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33298089.
nvd
CVE-2017-0482P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0482 [MEDIUM] CVE-2017-0482: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33090864.
nvd
CVE-2016-2495P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-06-13
CVE-2016-2495 [MEDIUM] CWE-20 CVE-2016-2495: SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5. SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28076789.
nvd
CVE-2016-3828P4MEDIUMCVSS 5.5v6.0v6.0.12016-08-05
CVE-2016-3828 [MEDIUM] CWE-172 CVE-2016-3828: decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.
nvd
CVE-2016-3827P4MEDIUMCVSS 5.5≤ 6.0.12016-08-05
CVE-2016-3827 [MEDIUM] CWE-172 CVE-2016-3827: codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mish codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28816956.
nvd
CVE-2016-6747P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6747 [MEDIUM] CWE-284 CVE-2016-6747: A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attack A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.
nvd
CVE-2016-6765P4MEDIUMCVSS 5.5v4.0v4.0.1+22 more2017-01-12
CVE-2016-6765 [MEDIUM] CWE-19 CVE-2016-6765: A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 7.0. Android ID: A-31449945.
nvd
CVE-2016-6767P4MEDIUMCVSS 5.5v4.0v4.0.1+15 more2017-01-12
CVE-2016-6767 [MEDIUM] CWE-399 CVE-2016-6767: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4. Android ID: A-31833604.
nvd
CVE-2016-6714P4MEDIUMCVSS 5.5≥ 6.0, ≤ 6.0.1v7.02016-11-25
CVE-2016-6714 [MEDIUM] CWE-284 CVE-2016-6714: A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 bef A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31092462.
nvd
CVE-2016-6764P4MEDIUMCVSS 5.5v4.0v4.0.1+24 more2017-01-12
CVE-2016-6764 [MEDIUM] CWE-399 CVE-2016-6764: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31681434.
nvd
CVE-2016-6678P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6678 [MEDIUM] CWE-200 CVE-2016-6678: The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtai The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 29914434.
nvd
CVE-2016-3818P4MEDIUMCVSS 5.5v4.0v4.0.1+14 more2016-07-11
CVE-2016-3818 [MEDIUM] CWE-284 CVE-2016-3818: libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang o libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28740702.
nvd
CVE-2017-0739P4MEDIUMCVSS 5.5v5.0v5.0.1+10 more2017-08-09
CVE-2017-0739 [MEDIUM] CWE-200 CVE-2017-0739: A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. V A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37712181.
nvd
CVE-2016-6686P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6686 [MEDIUM] CWE-200 CVE-2016-6686: The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensi The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30163101.
nvd
CVE-2016-6688P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6688 [MEDIUM] CWE-200 CVE-2016-6688: The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensi The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30593080.
nvd
CVE-2016-6677P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6677 [MEDIUM] CWE-200 CVE-2016-6677: The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sen The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.
nvd
CVE-2016-6687P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6687 [MEDIUM] CWE-200 CVE-2016-6687: The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensi The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30162222.
nvd
Google Android vulnerabilities | cvebase