cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 11 of 48
CVE-2017-0745P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-08-09
CVE-2017-0745 [HIGH] CWE-665 CVE-2017-0745: A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.
nvd
CVE-2017-0700P3HIGHCVSS 7.8vAndroid-7.1.1 Android-7.1.22017-07-06
CVE-2017-0700 [HIGH] CVE-2017-0700: A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7 A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.
nvd
CVE-2017-0678P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.22017-07-06
CVE-2017-0678 [HIGH] CVE-2017-0678: A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7. A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.
nvd
CVE-2017-0841P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-11-16
CVE-2017-0841 [HIGH] CWE-190 CVE-2017-0841: A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37723026.
nvd
CVE-2017-0835P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-11-16
CVE-2017-0835 [HIGH] CVE-2017-0835: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.
nvd
CVE-2017-0833P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-11-16
CVE-2017-0833 [HIGH] CVE-2017-0833: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62896384.
nvd
CVE-2017-0834P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-11-16
CVE-2017-0834 [HIGH] CWE-787 CVE-2017-0834: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63125953.
nvd
CVE-2017-0836P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-11-16
CVE-2017-0836 [HIGH] CWE-129 CVE-2017-0836: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64893226.
nvd
CVE-2017-0832P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-11-16
CVE-2017-0832 [HIGH] CVE-2017-0832: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62887820.
nvd
CVE-2017-13250P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13250 [HIGH] CWE-787 CVE-2017-13250: In ih264d_fmt_conv_420sp_to_420p of ih264d_utils.c, there is an out of bound write due to a missing In ih264d_fmt_conv_420sp_to_420p of ih264d_utils.c, there is an out of bound write due to a missing out of bounds check because of a multiplication error. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
nvd
CVE-2018-9553P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9553 [HIGH] CWE-415 CVE-2018-9553: In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure defau In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android
nvd
CVE-2018-9551P3HIGHCVSS 7.8vAndroid-92018-12-06
CVE-2018-9551 [HIGH] CWE-787 CVE-2018-9551: In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bound In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891548.
nvd
CVE-2016-6702P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+1 more2016-11-25
CVE-2016-6702 [HIGH] CWE-284 CVE-2016-6702: A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, an A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjp
nvd
CVE-2017-13277P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13277 [HIGH] CWE-787 CVE-2017-13277: In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bo In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-72165027.
nvd
CVE-2016-6703P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+3 more2016-11-25
CVE-2016-6703 [HIGH] CWE-284 CVE-2016-6703: A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0 A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker using a specially crafted payload to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote cod
nvd
CVE-2017-0382P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+4 more2017-01-12
CVE-2017-0382 [HIGH] CVE-2017-0382: A remote code execution vulnerability in the Framesequence library could enable an attacker using a A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2016-6701P3HIGHCVSS 7.8vAndroid-7.02016-11-25
CVE-2016-6701 [HIGH] CWE-119 CVE-2016-6701: A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an at A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637.
nvd
CVE-2017-0429P3HIGHCVSS 7.8vKernel-3.102017-02-08
CVE-2017-0429 [HIGH] CWE-787 CVE-2017-0429: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0428P3HIGHCVSS 7.8vKernel-3.102017-02-08
CVE-2017-0428 [HIGH] CWE-416 CVE-2017-0428: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0638P3HIGHCVSS 7.8vAndroid-7.1.1 Android-7.1.22017-06-14
CVE-2017-0638 [HIGH] CWE-787 CVE-2017-0638: A remote code execution vulnerability in System UI component could enable an attacker using a specia A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary code execution in an unprivileged process. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36368
nvd
Google Inc Android vulnerabilities | cvebase