Google Inc Android vulnerabilities

960 known vulnerabilities affecting google_inc/android.

Total CVEs
960
CISA KEV
0
Public exploits
22
Exploited in wild
0
Severity breakdown
CRITICAL70HIGH619MEDIUM267LOW4

Vulnerabilities

Page 1 of 48
CVE-2018-9578CRITICALCVSS 9.8vAndroid-92018-12-07
CVE-2018-9578 [CRITICAL] CWE-787 CVE-2018-9578: In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113261928.
cvelistv5nvd
CVE-2018-9518HIGHCVSS 7.8vAndroid Kernel2018-12-07
CVE-2018-9518 [HIGH] CWE-787 CVE-2018-9518: In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a mis In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.
cvelistv5nvd
CVE-2018-9573HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9573 [HIGH] CWE-787 CVE-2018-9573: In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due t In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116467350.
cvelistv5nvd
CVE-2018-9577HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9577 [HIGH] CWE-787 CVE-2018-9577: In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715937.
cvelistv5nvd
CVE-2018-9575HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9575 [HIGH] CWE-787 CVE-2018-9575: In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds wri In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619387.
cvelistv5nvd
CVE-2018-9574HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9574 [HIGH] CWE-787 CVE-2018-9574: In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bound In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619337.
cvelistv5nvd
CVE-2018-9571HIGHCVSS 8.8vAndroid-92018-12-07
CVE-2018-9571 [HIGH] CWE-787 CVE-2018-9571: In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound wr In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116020594.
cvelistv5nvd
CVE-2018-9570HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9570 [HIGH] CWE-787 CVE-2018-9570: In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-115375616.
cvelistv5nvd
CVE-2018-9576HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9576 [HIGH] CWE-787 CVE-2018-9576: In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bo In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715245.
cvelistv5nvd
CVE-2018-9569HIGHCVSS 8.8vAndroid-92018-12-07
CVE-2018-9569 [HIGH] CWE-787 CVE-2018-9569: In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound writ In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113885537.
cvelistv5nvd
CVE-2018-9517MEDIUMCVSS 6.7vAndroid Kernel2018-12-07
CVE-2018-9517 [MEDIUM] CWE-416 CVE-2018-9517: In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.
cvelistv5nvd
CVE-2018-9519MEDIUMCVSS 6.4vAndroid Kernel2018-12-07
CVE-2018-9519 [MEDIUM] CWE-362 CVE-2018-9519: In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-69808833.
cvelistv5nvd
CVE-2018-9556CRITICALCVSS 9.8vAndroid-92018-12-06
CVE-2018-9556 [CRITICAL] CWE-190 CVE-2018-9556: In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an inte In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113118184.
cvelistv5nvd
CVE-2018-9559HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9559 [HIGH] CWE-787 CVE-2018-9559: In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due t In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due to an uncaught error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-
cvelistv5nvd
CVE-2018-9562HIGHCVSS 7.5vAndroid-92018-12-06
CVE-2018-9562 [HIGH] CWE-125 CVE-2018-9562: In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parame In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113164621.
cvelistv5nvd
CVE-2018-9558HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9558 [HIGH] CWE-787 CVE-2018-9558: In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a miss In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC kernel with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8
cvelistv5nvd
CVE-2018-9538HIGHCVSS 7.8vAndroid-8.1 Android-92018-12-06
CVE-2018-9538 [HIGH] CWE-125 CVE-2018-9538: In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a po In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:
cvelistv5nvd
CVE-2018-9565HIGHCVSS 7.5vAndroid-166805582018-12-06
CVE-2018-9565 [HIGH] CWE-125 CVE-2018-9565: In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. Th In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.
cvelistv5nvd
CVE-2018-9550HIGHCVSS 7.8vAndroid-92018-12-06
CVE-2018-9550 [HIGH] CWE-787 CVE-2018-9550: In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing boun In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112660981.
cvelistv5nvd
CVE-2018-9555HIGHCVSS 8.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9555 [HIGH] CWE-787 CVE-2018-9555: In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds c In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
cvelistv5nvd
1 / 48Next →