cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 1 of 48
CVE-2017-13156P1HIGHCVSS 7.8ExploitedPoCv5.1.1v6.0+5 more2017-12-06
CVE-2017-13156 [HIGH] CWE-434 CVE-2017-13156: An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1 An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
nvd
CVE-2017-0561P2CRITICALCVSS 9.8PoCvKernel-3.10vKernel-3.182017-04-07
CVE-2017-0561 [CRITICAL] CWE-787 CVE-2017-0561: A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199105
nvd
CVE-2017-0781P2HIGHCVSS 8.8PoCv4.4.4v5.0.2+7 more2017-09-14
CVE-2017-0781 [HIGH] CWE-119 CVE-2017-0781: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.
nvd
CVE-2016-6754P2HIGHCVSS 8.8PoCvAndroid-5.0.2vAndroid-5.1.1+2 more2016-11-25
CVE-2016-6754 [HIGH] CWE-74 CVE-2016-6754: A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.
nvd
CVE-2017-13260P3HIGHCVSS 7.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13260 [HIGH] CWE-125 CVE-2017-13260: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177251.
nvd
CVE-2017-13261P3HIGHCVSS 7.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13261 [HIGH] CWE-125 CVE-2017-13261: In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a mis In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID:
nvd
CVE-2017-13258P3HIGHCVSS 7.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13258 [HIGH] CWE-125 CVE-2017-13258: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67863755.
nvd
CVE-2016-6707P3HIGHCVSS 7.8PoCvAndroid-6.0vAndroid-6.0.1+1 more2016-11-25
CVE-2016-6707 [HIGH] CWE-264 CVE-2016-6707: An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 be An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally acc
nvd
CVE-2017-13253P3HIGHCVSS 7.8PoCv8.0v8.12018-04-04
CVE-2017-13253 [HIGH] CWE-787 CVE-2017-13253: In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missi In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71389378.
nvd
CVE-2017-0569P3HIGHCVSS 7.0PoCvKernel-3.10vKernel-3.182017-04-07
CVE-2017-0569 [HIGH] CWE-131 CVE-2017-0569: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34198729. References: B-RB#
nvd
CVE-2017-13208P2CRITICALCVSS 9.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13208 [CRITICAL] CWE-119 CVE-2017-13208: In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7
nvd
CVE-2017-13216P3HIGHCVSS 7.8PoCvAndroid kernel2018-01-12
CVE-2017-13216 [HIGH] CWE-787 CVE-2017-13216: In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when access In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Andr
nvd
CVE-2017-0411P3HIGHCVSS 7.8PoCvAndroid-7.0vAndroid-7.1.12017-02-08
CVE-2017-0411 [HIGH] CWE-367 CVE-2017-0411: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd
CVE-2016-6772P3HIGHCVSS 7.8PoCvAndroid-5.0.2vAndroid-5.1.1+3 more2017-01-12
CVE-2016-6772 [HIGH] CWE-264 CVE-2016-6772: An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execu An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31856351.
nvd
CVE-2017-0412P3HIGHCVSS 7.8PoCvAndroid-7.0vAndroid-7.1.12017-02-08
CVE-2017-0412 [HIGH] CWE-367 CVE-2017-0412: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd
CVE-2017-13209P3HIGHCVSS 7.8PoCv8.0v8.12018-01-12
CVE-2017-13209 [HIGH] CWE-862 CVE-2017-13209: In the ServiceManager::add function in the hardware service manager, there is an insecure permission In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execut
nvd
CVE-2018-9515P3HIGHCVSS 7.8PoCvAndroid kernel2018-10-02
CVE-2018-9515 [HIGH] CWE-119 CVE-2018-9515: In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to impro In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111641492 References: N/A
nvd
CVE-2017-13236P3HIGHCVSS 7.8PoCv8.0v8.12018-02-12
CVE-2017-13236 [HIGH] CWE-732 CVE-2017-13236: In the KeyStore service, there is a permissions bypass that allows access to protected resources. Th In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.
nvd
CVE-2018-9488P3HIGHCVSS 7.8PoCvAndroid-8.0 Android-8.1 Android-9.02018-11-06
CVE-2018-9488 [HIGH] CWE-863 CVE-2018-9488: In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restrict In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-110107376.
nvd
CVE-2017-13262P3MEDIUMCVSS 6.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13262 [MEDIUM] CWE-125 CVE-2017-13262: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length dec In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID:
nvd
1 / 48Next →
Google Inc Android vulnerabilities | cvebase