cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 10 of 48
CVE-2018-9514P3HIGHCVSS 7.8vAndroid kernel2018-10-02
CVE-2018-9514 [HIGH] CWE-416 CVE-2018-9514: In sdcardfs_open of file.c, there is a possible Use After Free due to an unusual root cause. This co In sdcardfs_open of file.c, there is a possible Use After Free due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111642636 References: N/A
nvd
CVE-2018-9557P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.22018-12-06
CVE-2018-9557 [HIGH] CWE-763 CVE-2018-9557: In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninit In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2. Android ID: A-35385357.
nvd
CVE-2017-0822P3CRITICALCVSS 9.8v6.0.1v7.0+3 more2017-10-04
CVE-2017-0822 [CRITICAL] CVE-2017-0822: An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63787722.
nvd
CVE-2017-0528P3HIGHCVSS 7.8vKernel-3.182017-03-08
CVE-2017-0528 [HIGH] CVE-2017-0528: An elevation of privilege vulnerability in the kernel security subsystem could enable a local malici An elevation of privilege vulnerability in the kernel security subsystem could enable a local malicious application to to execute code in the context of a privileged process. This issue is rated as High because it is a general bypass for a kernel level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.18. Android ID: A-3335
nvd
CVE-2016-6789P3HIGHCVSS 7.8vKernel-3.182017-01-12
CVE-2016-6789 [HIGH] CWE-284 CVE-2016-6789: An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application
nvd
CVE-2017-0455P3HIGHCVSS 7.8vKernel-3.182017-03-08
CVE-2017-0455 [HIGH] CWE-200 CVE-2017-0455: An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local mali An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code within the context of the bootloader. This issue is rated as High because it is a general bypass for a bootloader level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.
nvd
CVE-2016-6759P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-01-12
CVE-2016-6759 [HIGH] CWE-284 CVE-2016-6759: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious appl An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2016-6758P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-01-12
CVE-2016-6758 [HIGH] CWE-284 CVE-2016-6758: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious appl An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2016-6761P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-01-12
CVE-2016-6761 [HIGH] CWE-284 CVE-2016-6761: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious appl An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2016-6760P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-01-12
CVE-2016-6760 [HIGH] CWE-284 CVE-2016-6760: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious appl An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2017-0505P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0505 [HIGH] CVE-2017-0505: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0760P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-09-08
CVE-2017-0760 [HIGH] CWE-755 CVE-2017-0760: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.
nvd
CVE-2017-0764P3HIGHCVSS 7.8v4.4.4v5.0.2+7 more2017-09-08
CVE-2017-0764 [HIGH] CVE-2017-0764: A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.
nvd
CVE-2017-0761P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-09-08
CVE-2017-0761 [HIGH] CWE-119 CVE-2017-0761: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.
nvd
CVE-2017-0758P3HIGHCVSS 7.8v5.0.2v5.1.1+5 more2017-09-08
CVE-2017-0758 [HIGH] CWE-119 CVE-2017-0758: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.
nvd
CVE-2017-0722P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-08-09
CVE-2017-0722 [HIGH] CVE-2017-0722: A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Androi A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.
nvd
CVE-2017-0714P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-08-09
CVE-2017-0714 [HIGH] CVE-2017-0714: A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Androi A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.
nvd
CVE-2017-0718P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-08-09
CVE-2017-0718 [HIGH] CVE-2017-0718: A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Andro A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.
nvd
CVE-2017-0720P3HIGHCVSS 7.8v5.0.2v5.1.1+5 more2017-08-09
CVE-2017-0720 [HIGH] CWE-252 CVE-2017-0720: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.
nvd
CVE-2017-0719P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-08-09
CVE-2017-0719 [HIGH] CWE-772 CVE-2017-0719: A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Andro A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.
nvd
Google Inc Android vulnerabilities | cvebase