cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 3 of 48
CVE-2016-10230P3CRITICALCVSS 9.8vAndroid kernel2018-04-04
CVE-2016-10230 [CRITICAL] CWE-264 CVE-2016-10230: A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: And A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.
nvd
CVE-2018-9476P3CRITICALCVSS 9.8vAndroid-8.0 Android-8.12018-10-02
CVE-2018-9476 [CRITICAL] CWE-416 CVE-2018-9476: In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper loc In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper locking. This could lead to remote escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-10969911
nvd
CVE-2017-13160P3CRITICALCVSS 9.8v7.0v7.1.1+2 more2017-12-06
CVE-2017-13160 [CRITICAL] CWE-125 CVE-2017-13160: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-37160362.
nvd
CVE-2018-9446P3CRITICALCVSS 9.8vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9446 [CRITICAL] CWE-787 CVE-2018-9446: In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memo In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Andro
nvd
CVE-2018-9556P3CRITICALCVSS 9.8vAndroid-92018-12-06
CVE-2018-9556 [CRITICAL] CWE-190 CVE-2018-9556: In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an inte In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113118184.
nvd
CVE-2016-8439P3CRITICALCVSS 9.8vKernel-3.182017-01-12
CVE-2016-8439 [CRITICAL] CWE-119 CVE-2016-8439: Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of buffer size checking. Product: Android. Versions: Kernel 3.18. Android ID: A-31625204. References: QC-CR#1027804.
nvd
CVE-2018-9578P3CRITICALCVSS 9.8vAndroid-92018-12-07
CVE-2018-9578 [CRITICAL] CWE-787 CVE-2018-9578: In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113261928.
nvd
CVE-2017-0782P3HIGHCVSS 8.8v4.4.4v5.0.2+7 more2017-09-14
CVE-2017-0782 [HIGH] CWE-120 CVE-2017-0782: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146237.
nvd
CVE-2018-9537P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9537 [HIGH] CWE-787 CVE-2018-9537: In CAacDecoder_DecodeFrame of aacdecode.cpp, there is a possible out-of-bounds write due to a missin In CAacDecoder_DecodeFrame of aacdecode.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891564
nvd
CVE-2018-9521P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9521 [HIGH] CWE-787 CVE-2018-9521: In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an inco In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-111874331
nvd
CVE-2017-13228P3HIGHCVSS 8.8v6.0v6.0.1+5 more2018-02-12
CVE-2017-13228 [HIGH] CWE-787 CVE-2017-13228: In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount bei In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A
nvd
CVE-2017-13230P3HIGHCVSS 8.8v7.0v7.1.1+3 more2018-02-12
CVE-2017-13230 [HIGH] CWE-787 CVE-2017-13230: In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_widt In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65483665.
nvd
CVE-2018-9504P3HIGHCVSS 8.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9504 [HIGH] CWE-787 CVE-2018-9504: In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrec In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2017-13255P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-04-04
CVE-2017-13255 [HIGH] CWE-787 CVE-2017-13255: In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68776054.
nvd
CVE-2016-8440P3CRITICALCVSS 9.8vKernel-3.182017-01-12
CVE-2016-8440 [CRITICAL] CWE-119 CVE-2016-8440: Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call m Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747.
nvd
CVE-2018-9529P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9529 [HIGH] CWE-787 CVE-2018-9529: In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due t In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112551874
nvd
CVE-2018-9528P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9528 [HIGH] CWE-787 CVE-2018-9528: In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write d In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112551721
nvd
CVE-2018-9534P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9534 [HIGH] CWE-787 CVE-2018-9534: In ixheaacd_mps_getstridemap of ixheaacd_mps_parse.c there is a possible out of bounds write due to In ixheaacd_mps_getstridemap of ixheaacd_mps_parse.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112857941
nvd
CVE-2018-9532P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9532 [HIGH] CWE-787 CVE-2018-9532: In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112765917
nvd
CVE-2018-9535P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9535 [HIGH] CWE-787 CVE-2018-9535: In ixheaacd_reset_acelp_data_fix of ixheaacd_lpc.c there is a possible out of bounds write due to a In ixheaacd_reset_acelp_data_fix of ixheaacd_lpc.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112858010
nvd
Google Inc Android vulnerabilities | cvebase