Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 15 of 48
CVE-2017-0476P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0476 [HIGH] CWE-119 CVE-2017-0476: A remote code execution vulnerability in AOSP Messaging could enable an attacker using a specially c
A remote code execution vulnerability in AOSP Messaging could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of an unprivileged process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. An
nvd
CVE-2017-0427P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-02-08
CVE-2017-0427 [HIGH] CVE-2017-0427: An elevation of privilege vulnerability in the kernel file system could enable a local malicious app
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions:
nvd
CVE-2017-0477P3HIGHCVSS 7.8vAndroid-7.1.12017-03-08
CVE-2017-0477 [HIGH] CWE-119 CVE-2017-0477: A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted f
A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-33621647.
nvd
CVE-2017-0671P3HIGHCVSS 7.8vAndroid-4.4.42017-07-06
CVE-2017-0671 [HIGH] CVE-2017-0671: A remote code execution vulnerability in the Android libraries. Product: Android. Versions: 4.4.4. A
A remote code execution vulnerability in the Android libraries. Product: Android. Versions: 4.4.4. Android ID: A-34514762.
nvd
CVE-2017-13225P3HIGHCVSS 7.8vAndroid kernel2018-01-12
CVE-2017-13225 [HIGH] CWE-119 CVE-2017-13225: In libMtkOmxVdec.so there is a possible heap buffer overflow. This could lead to a remote elevation
In libMtkOmxVdec.so there is a possible heap buffer overflow. This could lead to a remote elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38308024. References: M-ALPS03495789.
nvd
CVE-2017-0430P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-02-08
CVE-2017-0430 [HIGH] CVE-2017-0430: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Version
nvd
CVE-2017-0504P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0504 [HIGH] CVE-2017-0504: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0475P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0475 [HIGH] CWE-20 CVE-2017-0475: An elevation of privilege vulnerability in the recovery verifier could enable a local malicious appl
An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ver
nvd
CVE-2017-0756P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-09-08
CVE-2017-0756 [HIGH] CWE-367 CVE-2017-0756: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073.
nvd
CVE-2017-0544P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-04-07
CVE-2017-0544 [HIGH] CWE-672 CVE-2017-0544: An elevation of privilege vulnerability in CameraBase could enable a local malicious application to
An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code. This issue is rated as High because it is a local arbitrary code execution in a privileged process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31992879.
nvd
CVE-2016-6700P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+1 more2016-11-25
CVE-2016-6700 [HIGH] CWE-264 CVE-2016-6700: An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.
An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require ref
nvd
CVE-2017-0481P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0481 [HIGH] CWE-120 CVE-2017-0481: An elevation of privilege vulnerability in NFC could enable a proximate attacker to execute arbitrar
An elevation of privilege vulnerability in NFC could enable a proximate attacker to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2
nvd
CVE-2017-0503P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0503 [HIGH] CVE-2017-0503: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0509P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0509 [HIGH] CVE-2017-0509: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Version
nvd
CVE-2017-0502P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0502 [HIGH] CVE-2017-0502: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0501P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0501 [HIGH] CVE-2017-0501: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0500P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0500 [HIGH] CVE-2017-0500: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0506P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0506 [HIGH] CVE-2017-0506: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0740P3HIGHCVSS 7.8vAndroid kernel2017-08-09
CVE-2017-0740 [HIGH] CVE-2017-0740: A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions:
A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.
nvd
CVE-2017-0713P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-08-09
CVE-2017-0713 [HIGH] CVE-2017-0713: A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions:
A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.
nvd