cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 16 of 48
CVE-2016-6735P3HIGHCVSS 7.8vKernel-3.182016-11-25
CVE-2016-6735 [HIGH] CWE-264 CVE-2016-6735: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2016-6734P3HIGHCVSS 7.8vKernel-3.182016-11-25
CVE-2016-6734 [HIGH] CWE-264 CVE-2016-6734: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2017-0522P3HIGHCVSS 7.8vn/a2017-03-08
CVE-2017-0522 [HIGH] CVE-2017-0522: An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High due to the possibility of local arbitrary code execution in a privileged process. Product: Android. Versions: N/A. Android ID: A-32916158. References: M-ALPS0303251
nvd
CVE-2016-8436P3HIGHCVSS 7.8vKernel-3.182017-01-12
CVE-2016-8436 [HIGH] CWE-264 CVE-2016-8436: An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-10275P3HIGHCVSS 7.8vn/a2017-05-12
CVE-2016-10275 [HIGH] CWE-264 CVE-2016-10275: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android
nvd
CVE-2016-6736P3HIGHCVSS 7.8vKernel-3.182016-11-25
CVE-2016-6736 [HIGH] CWE-264 CVE-2016-6736: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2016-6729P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6729 [HIGH] CWE-264 CVE-2016-6729: An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 coul An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair t
nvd
CVE-2016-8423P3HIGHCVSS 7.8vn/a2017-01-12
CVE-2016-8423 [HIGH] CWE-264 CVE-2016-8423: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-8422P3HIGHCVSS 7.8vn/a2017-01-12
CVE-2016-8422 [HIGH] CWE-264 CVE-2016-8422: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-10276P3HIGHCVSS 7.8vn/a2017-05-12
CVE-2016-10276 [HIGH] CWE-264 CVE-2016-10276: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android
nvd
CVE-2017-13251P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13251 [HIGH] CWE-787 CVE-2017-13251: In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when running multi threaded with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8
nvd
CVE-2017-0861P3HIGHCVSS 7.8vAndroid kernel2017-11-16
CVE-2017-0861 [HIGH] CWE-416 CVE-2017-0861: Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel Use-after-free vulnerability in the snd_pcm_info function in the ALSA subsystem in the Linux kernel allows attackers to gain privileges via unspecified vectors.
nvd
CVE-2017-13215P3HIGHCVSS 7.8vAndroid kernel2018-01-12
CVE-2017-13215 [HIGH] CVE-2017-13215: A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
nvd
CVE-2018-9489P3HIGHCVSS 7.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-11-06
CVE-2018-9489 [HIGH] CWE-200 CVE-2018-9489: When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network information. This could lead to information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2018-9501P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9501 [HIGH] CVE-2018-9501: In the SetupWizard, there is a possible Factory Reset Protection bypass due to a permissions bypass. In the SetupWizard, there is a possible Factory Reset Protection bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A
nvd
CVE-2018-9357P3HIGHCVSS 7.8vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9357 [HIGH] CWE-787 CVE-2018-9357: In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds che In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8
nvd
CVE-2017-13181P3HIGHCVSS 7.8v7.0v7.1.1+3 more2018-01-12
CVE-2017-13181 [HIGH] CWE-415 CVE-2017-13181: In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to no In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer. This could lead to an local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions
nvd
CVE-2018-9523P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-11-14
CVE-2018-9523 [HIGH] CWE-20 CVE-2018-9523: In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2
nvd
CVE-2017-13287P3HIGHCVSS 7.8v6.0.1v7.0+4 more2018-04-04
CVE-2017-13287 [HIGH] CWE-20 CVE-2017-13287: In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to local escalation of privilege if mPayload in writeToParcel were null, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0,
nvd
CVE-2018-9558P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9558 [HIGH] CWE-787 CVE-2018-9558: In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a miss In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC kernel with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8
nvd
Google Inc Android vulnerabilities | cvebase