cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 17 of 48
CVE-2018-9545P3HIGHCVSS 7.8vAndroid-92018-11-14
CVE-2018-9545 [HIGH] CWE-787 CVE-2018-9545: In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bound In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113111784
nvd
CVE-2018-9513P3HIGHCVSS 7.8vAndroid kernel2018-10-02
CVE-2018-9513 [HIGH] CWE-415 CVE-2018-9513: In copy_process of fork.c, there is possible memory corruption due to a double free. This could lead In copy_process of fork.c, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111081202 References: N/A
nvd
CVE-2018-9560P3HIGHCVSS 7.8vAndroid-92018-12-06
CVE-2018-9560 [HIGH] CWE-787 CVE-2018-9560: In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth service with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-79946737.
nvd
CVE-2017-0829P3CRITICALCVSS 9.8vAndroid kernel2017-10-04
CVE-2017-0829 [CRITICAL] CVE-2017-0829: An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Andr An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.
nvd
CVE-2018-9580P3CRITICALCVSS 9.8vAndroid kernel2018-11-14
CVE-2018-9580 [CRITICAL] CVE-2018-9580: A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android ke A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-76222002.
nvd
CVE-2017-0847P3CRITICALCVSS 9.8v8.02017-11-16
CVE-2017-0847 [CRITICAL] CWE-276 CVE-2017-0847: An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: An An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.
nvd
CVE-2017-0386P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+4 more2017-01-12
CVE-2017-0386 [HIGH] CVE-2017-0386: An elevation of privilege vulnerability in the libnl library could enable a local malicious applicat An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Version
nvd
CVE-2017-0417P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0417 [HIGH] CWE-787 CVE-2017-0417: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0415P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0415 [HIGH] CVE-2017-0415: An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 6.0
nvd
CVE-2017-0419P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0419 [HIGH] CVE-2017-0419: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd
CVE-2017-0418P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0418 [HIGH] CWE-787 CVE-2017-0418: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0416P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0416 [HIGH] CWE-787 CVE-2017-0416: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2016-6704P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+4 more2016-11-25
CVE-2016-6704 [HIGH] CWE-264 CVE-2016-6704: An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0 An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local ac
nvd
CVE-2017-0749P3HIGHCVSS 7.8vAndroid kernel2017-08-09
CVE-2017-0749 [HIGH] CVE-2017-0749: A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Version A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.
nvd
CVE-2017-0450P3HIGHCVSS 7.8vn/a2017-02-08
CVE-2017-0450 [HIGH] CVE-2017-0450: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.
nvd
CVE-2017-0562P3HIGHCVSS 7.8vn/a2017-04-07
CVE-2017-0562 [HIGH] CVE-2017-0562: An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local mali An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2017-0422P3HIGHCVSS 7.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0422 [HIGH] CWE-20 CVE-2017-0422: A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially cr A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32322088.
nvd
CVE-2017-0595P3HIGHCVSS 7.8v4.4.4v5.0.2+5 more2017-05-12
CVE-2017-0595 [HIGH] CVE-2017-0595: An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malici An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Andr
nvd
CVE-2017-0594P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0594 [HIGH] CWE-120 CVE-2017-0594: An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Me An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessibl
nvd
CVE-2017-0384P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0384 [HIGH] CVE-2017-0384: An elevation of privilege vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audi An elevation of privilege vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a thi
nvd
Google Inc Android vulnerabilities | cvebase