Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 13 of 48
CVE-2017-13217P3HIGHCVSS 7.8vAndroid kernel2018-01-12
CVE-2017-13217 [HIGH] CWE-787 CVE-2017-13217: In DisplayFtmItem in the bootloader, there is an out-of-bounds write due to reading a string without
In DisplayFtmItem in the bootloader, there is an out-of-bounds write due to reading a string without verifying that it's null-terminated. This could lead to a secure boot bypass and a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitat
nvd
CVE-2017-13288P3HIGHCVSS 7.8v8.0v8.12018-04-04
CVE-2017-13288 [HIGH] CWE-682 CVE-2017-13288: In writeToParcel and readFromParcel of PeriodicAdvertisingReport.java, there is a permission bypass
In writeToParcel and readFromParcel of PeriodicAdvertisingReport.java, there is a permission bypass due to a 64/32bit int mismatch. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Andr
nvd
CVE-2017-13180P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-01-12
CVE-2017-13180 [HIGH] CWE-416 CVE-2017-13180: In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use af
In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution priv
nvd
CVE-2018-9492P3HIGHCVSS 7.8vAndroid-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9492 [HIGH] CWE-863 CVE-2018-9492: In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions byp
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-111934948
nvd
CVE-2018-9525P3HIGHCVSS 7.8vAndroid-92018-11-14
CVE-2018-9525 [HIGH] CVE-2018-9525: In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings
In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings.slice.action.WIFI_CHANGED, there is a possible permissions bypass due to a confused deputy. This could lead to local escalation of privilege, allowing a local attacker to change device settings, with no additional execution privileges needed. User interaction is
nvd
CVE-2018-9522P3HIGHCVSS 7.8vAndroid-92018-11-14
CVE-2018-9522 [HIGH] CWE-787 CVE-2018-9522: In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write
In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write due to unnecessary functionality which may be abused. This could lead to local escalation of privilege in the system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Andr
nvd
CVE-2017-13293P3HIGHCVSS 7.8vAndroid kernel2018-04-04
CVE-2017-13293 [HIGH] CWE-787 CVE-2017-13293: In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a m
In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701.
nvd
CVE-2018-9547P3HIGHCVSS 7.8vAndroid-8.1 Android-92018-12-06
CVE-2018-9547 [HIGH] CWE-20 CVE-2018-9547: In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-114223584.
nvd
CVE-2018-9526P3HIGHCVSS 7.5vAndroid-92018-11-14
CVE-2018-9526 [HIGH] CWE-200 CVE-2018-9526: In device configuration data, there is an improperly configured setting. This could lead to remote d
In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112159033
nvd
CVE-2017-13247P3HIGHCVSS 7.8vAndroid kernel2018-02-12
CVE-2017-13247 [HIGH] CWE-862 CVE-2017-13247: In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader loc
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-71486645.
nvd
CVE-2018-9567P3HIGHCVSS 7.8vAndroid kernel2018-12-06
CVE-2018-9567 [HIGH] CVE-2018-9567: On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despi
On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different signing keys. This may lead to local escalation of privilege if people are relying on those fingerprints to determine what version of the OS the device is running, with System execution privileges needed. User interaction is not needed for expl
nvd
CVE-2016-10233P3CRITICALCVSS 9.8vAndroid kernel2018-04-04
CVE-2016-10233 [CRITICAL] CWE-264 CVE-2016-10233: An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: An
An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.
nvd
CVE-2017-13232P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-02-12
CVE-2017-13232 [HIGH] CWE-200 CVE-2017-13232: In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that m
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Andro
nvd
CVE-2017-13280P3HIGHCVSS 7.5v6.0v6.0.1+5 more2018-04-04
CVE-2017-13280 [HIGH] CWE-125 CVE-2017-13280: In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds r
In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Androi
nvd
CVE-2017-0828P3CRITICALCVSS 9.8vAndroid kernel2017-10-04
CVE-2017-0828 [CRITICAL] CVE-2017-0828: An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Androi
An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.
nvd
CVE-2017-0824P3CRITICALCVSS 9.8vAndroid kernel2017-10-04
CVE-2017-0824 [CRITICAL] CVE-2017-0824: An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: And
An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.
nvd
CVE-2016-6728P3HIGHCVSS 7.8vKernel-3.4vKernel-3.10+1 more2016-11-25
CVE-2016-6728 [HIGH] CWE-264 CVE-2016-6728: An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 cou
An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair
nvd
CVE-2017-0763P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-09-08
CVE-2017-0763 [HIGH] CVE-2017-0763: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62534693.
nvd
CVE-2017-0753P3HIGHCVSS 7.8v7.1.1v7.1.2+1 more2017-09-08
CVE-2017-0753 [HIGH] CVE-2017-0753: A remote code execution vulnerability in the Android libraries (libgdx). Product: Android. Versions:
A remote code execution vulnerability in the Android libraries (libgdx). Product: Android. Versions: 7.1.1, 7.1.2, 8.0. Android ID: A-62218744.
nvd
CVE-2017-0759P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-09-08
CVE-2017-0759 [HIGH] CWE-755 CVE-2017-0759: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.
nvd