Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 2 of 48
CVE-2017-0785P3MEDIUMCVSS 6.5PoCv4.4.4v5.0.2+7 more2017-09-14
CVE-2017-0785 [MEDIUM] CWE-200 CVE-2017-0785: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
nvd
CVE-2017-13282P3CRITICALCVSS 9.8v7.0v7.1.1+3 more2018-04-04
CVE-2017-13282 [CRITICAL] CWE-119 CVE-2017-13282: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603315.
nvd
CVE-2018-9356P3CRITICALCVSS 9.8vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9356 [CRITICAL] CWE-415 CVE-2018-9356: In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. Thi
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1
nvd
CVE-2018-9355P3CRITICALCVSS 9.8vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9355 [CRITICAL] CWE-787 CVE-2018-9355: In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missin
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Andr
nvd
CVE-2017-13177P3CRITICALCVSS 9.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13177 [CRITICAL] CWE-119 CVE-2017-13177: In several functions of libhevc, NEON registers are not preserved. This could lead to remote code ex
In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68320413.
nvd
CVE-2017-13178P3CRITICALCVSS 9.8v6.0.1v7.0+4 more2018-01-12
CVE-2017-13178 [CRITICAL] CWE-416 CVE-2017-13178: In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0
nvd
CVE-2017-13283P3CRITICALCVSS 9.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-04-04
CVE-2017-13283 [CRITICAL] CWE-787 CVE-2017-13283: In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the
In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71
nvd
CVE-2017-13266P3CRITICALCVSS 9.8v5.1.1v6.0+6 more2018-04-04
CVE-2017-13266 [CRITICAL] CWE-119 CVE-2017-13266: In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bo
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478941.
nvd
CVE-2017-13179P3CRITICALCVSS 9.8v6.0.1v7.0+4 more2018-01-12
CVE-2017-13179 [CRITICAL] CWE-416 CVE-2017-13179: In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-
In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_codec_obj and ps_create_op->s_ivd_create_op_t.pv_handle point to the same memory and ps_codec_obj could be freed without clearing ps_create_op->s_ivd_create_op_t.pv_handle. This could lead to remote c
nvd
CVE-2017-13281P3CRITICALCVSS 9.8v8.0v8.12018-04-04
CVE-2017-13281 [CRITICAL] CWE-119 CVE-2017-13281: In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an in
In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71603262.
nvd
CVE-2017-13292P3CRITICALCVSS 9.8vAndroid kernel2018-04-04
CVE-2017-13292 [CRITICAL] CWE-787 CVE-2017-13292: In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bo
In wl_get_assoc_ies of wl_cfg80211.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-70722061. References: B-V2018010201.
nvd
CVE-2016-8418P3CRITICALCVSS 9.8vn/a2017-02-08
CVE-2016-8418 [CRITICAL] CWE-284 CVE-2016-8418: A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker t
A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Product: Android. Versions: N/A. Android ID: A-32652894. References: QC-CR#1077457
nvd
CVE-2017-13284P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13284 [CRITICAL] CWE-20 CVE-2017-13284: In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval
In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1.
nvd
CVE-2017-13285P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13285 [CRITICAL] CWE-787 CVE-2017-13285: In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write
In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7
nvd
CVE-2018-9450P3HIGHCVSS 8.8vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9450 [HIGH] CWE-787 CVE-2018-9450: In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing
In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8
nvd
CVE-2016-6725P3CRITICALCVSS 9.8vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6725 [CRITICAL] CWE-284 CVE-2016-6725: A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 cou
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#10
nvd
CVE-2017-13272P3CRITICALCVSS 9.8v7.0v7.1.1+3 more2018-04-04
CVE-2017-13272 [CRITICAL] CWE-416 CVE-2017-13272: In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free.
In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67110137.
nvd
CVE-2017-13229P3CRITICALCVSS 9.8v7.0v7.1.1+3 more2018-02-12
CVE-2017-13229 [CRITICAL] CWE-20 CVE-2017-13229: A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versio
A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68160703.
nvd
CVE-2017-13267P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13267 [CRITICAL] CWE-119 CVE-2017-13267: In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bo
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-6947900
nvd
CVE-2018-9445P4MEDIUMCVSS 6.8PoCvAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9445 [MEDIUM] CWE-22 CVE-2018-9445: In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-
nvd