Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 12 of 48
CVE-2017-0563P3HIGHCVSS 7.8vKernel-3.102017-04-07
CVE-2017-0563 [HIGH] CWE-345 CVE-2017-0563: An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Androi
nvd
CVE-2018-9570P3HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9570 [HIGH] CWE-787 CVE-2018-9570: In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to
In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-115375616.
nvd
CVE-2018-9455P3HIGHCVSS 7.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9455 [HIGH] CWE-125 CVE-2018-9455: In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2016-6768P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+3 more2017-01-12
CVE-2016-6768 [HIGH] CWE-284 CVE-2016-6768: A remote code execution vulnerability in the Framesequence library could enable an attacker using a
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2
nvd
CVE-2017-13276P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13276 [HIGH] CWE-119 CVE-2017-13276: In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a
In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a missing bounds check. This could lead to a remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70637599.
nvd
CVE-2017-13168P3HIGHCVSS 7.8vAndroid kernel2017-12-06
CVE-2017-13168 [HIGH] CWE-732 CVE-2017-13168: An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Andro
An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
nvd
CVE-2018-9542P3HIGHCVSS 7.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-11-14
CVE-2018-9542 [HIGH] CWE-125 CVE-2018-9542: In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing
In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Andr
nvd
CVE-2018-9541P3HIGHCVSS 7.5vAndroid-92018-11-14
CVE-2018-9541 [HIGH] CWE-125 CVE-2018-9541: In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing
In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 And
nvd
CVE-2018-9540P3HIGHCVSS 7.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-11-14
CVE-2018-9540 [HIGH] CWE-125 CVE-2018-9540: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a miss
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-
nvd
CVE-2017-13166P3HIGHCVSS 7.8vAndroid kernel2017-12-06
CVE-2017-13166 [HIGH] CWE-787 CVE-2017-13166: An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions:
An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.
nvd
CVE-2018-9562P3HIGHCVSS 7.5vAndroid-92018-12-06
CVE-2018-9562 [HIGH] CWE-125 CVE-2018-9562: In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parame
In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113164621.
nvd
CVE-2017-13291P3HIGHCVSS 7.5v7.0v7.1.1+3 more2018-04-04
CVE-2017-13291 [HIGH] CWE-476 CVE-2017-13291: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible NULL pointer dereference due to
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible NULL pointer dereference due to missing bounds checks. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603553.
nvd
CVE-2017-13286P3HIGHCVSS 7.8v8.0v8.12018-04-04
CVE-2017-13286 [HIGH] CWE-502 CVE-2017-13286: In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to
In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.
nvd
CVE-2017-13220P3HIGHCVSS 7.8vAndroid kernel2018-01-12
CVE-2017-13220 [HIGH] CWE-843 CVE-2017-13220: An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: An
An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.
nvd
CVE-2018-9518P3HIGHCVSS 7.8vAndroid Kernel2018-12-07
CVE-2018-9518 [HIGH] CWE-787 CVE-2018-9518: In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a mis
In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.
nvd
CVE-2018-9385P3HIGHCVSS 7.8vAndroid kernel2018-11-06
CVE-2018-9385 [HIGH] CWE-787 CVE-2018-9385: In driver_override_store of bus.c, there is a possible out of bounds write due to an incorrect bound
In driver_override_store of bus.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-74128061 References: Upstream kernel.
nvd
CVE-2018-9415P3HIGHCVSS 7.8vAndroid kernel2018-11-06
CVE-2018-9415 [HIGH] CWE-415 CVE-2018-9415: In driver_override_store and driver_override_show of bus.c, there is a possible double free due to i
In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69129004 References: Upstream kernel.
nvd
CVE-2017-13184P3HIGHCVSS 7.8v8.0v8.12018-01-12
CVE-2017-13184 [HIGH] CWE-416 CVE-2017-13184: In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyn
In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android I
nvd
CVE-2017-13210P3HIGHCVSS 7.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13210 [HIGH] CWE-787 CVE-2017-13210: In CameraDeviceClient::submitRequestList of CameraDeviceClient.cpp, there is an out-of-bounds write
In CameraDeviceClient::submitRequestList of CameraDeviceClient.cpp, there is an out-of-bounds write if metadataSize is too small. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5
nvd
CVE-2018-9465P3HIGHCVSS 7.8vAndroid kernel2018-11-06
CVE-2018-9465 [HIGH] CWE-416 CVE-2018-9465: In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after fr
In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.
nvd