Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 35 of 48
CVE-2016-10281P4HIGHCVSS 7.0vn/a2017-05-12
CVE-2016-10281 [HIGH] CWE-264 CVE-2016-10281: An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local maliciou
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175647. References: M-ALPS02696475.
nvd
CVE-2016-10280P4HIGHCVSS 7.0vn/a2017-05-12
CVE-2016-10280 [HIGH] CWE-264 CVE-2016-10280: An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local maliciou
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.
nvd
CVE-2014-9909P4HIGHCVSS 7.0vn/a2017-01-18
CVE-2014-9909 [HIGH] CWE-264 CVE-2014-9909: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31676542. References: B-RB#26684.
nvd
CVE-2017-13257P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-04-04
CVE-2017-13257 [MEDIUM] CWE-416 CVE-2017-13257: In bta_pan_data_buf_ind_cback of bta_pan_act.cc there is a use after free that can result in an out
In bta_pan_data_buf_ind_cback of bta_pan_act.cc there is a use after free that can result in an out of bounds read of memory allocated via malloc. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0,
nvd
CVE-2017-0728P4HIGHCVSS 7.8v5.0.2v5.1.1+5 more2017-08-09
CVE-2017-0728 [HIGH] CVE-2017-0728: A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. V
A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37469795.
nvd
CVE-2017-6423P4HIGHCVSS 7.0vAndroid kernel2018-04-04
CVE-2017-6423 [HIGH] CVE-2017-6423: An elevation of privilege vulnerability in the Qualcomm kyro L2 driver. Product: Android. Versions:
An elevation of privilege vulnerability in the Qualcomm kyro L2 driver. Product: Android. Versions: Android kernel. Android ID: A-32831370. References: QC-CR#1103158.
nvd
CVE-2018-9502P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9502 [MEDIUM] CWE-125 CVE-2018-9502: In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missi
In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.
nvd
CVE-2018-9347P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-11-14
CVE-2018-9347 [MEDIUM] CWE-20 CVE-2018-9347: In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infi
In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary DoS with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Andro
nvd
CVE-2017-13233P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-02-12
CVE-2017-13233 [MEDIUM] CWE-400 CVE-2017-13233: In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This coul
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62851602.
nvd
CVE-2017-6424P4HIGHCVSS 7.0vAndroid kernel2018-04-04
CVE-2017-6424 [HIGH] CVE-2017-6424: An elevation of privilege vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: And
An elevation of privilege vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-32086742. References: QC-CR#1102648.
nvd
CVE-2017-13273P4HIGHCVSS 7.0vAndroid kernel2018-02-15
CVE-2017-13273 [HIGH] CVE-2017-13273: In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local ele
In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-65853158.
nvd
CVE-2018-9517P4MEDIUMCVSS 6.7vAndroid Kernel2018-12-07
CVE-2018-9517 [MEDIUM] CWE-416 CVE-2018-9517: In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to
In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.
nvd
CVE-2018-9509P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9509 [MEDIUM] CWE-125 CVE-2018-9509: In smp_proc_master_id of smp_act.cc, there is a possible out of bounds read due to a missing bounds
In smp_proc_master_id of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2018-9510P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9510 [MEDIUM] CWE-125 CVE-2018-9510: In smp_proc_enc_info of smp_act.cc, there is a possible out of bounds read due to a missing bounds c
In smp_proc_enc_info of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2018-9506P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9506 [MEDIUM] CWE-125 CVE-2018-9506: In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds chec
In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.
nvd
CVE-2017-13234P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-02-12
CVE-2017-13234 [MEDIUM] CWE-772 CVE-2017-13234: In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. Thi
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68159767.
nvd
CVE-2016-6709P4MEDIUMCVSS 5.9vAndroid-6.0vAndroid-6.0.1+1 more2016-11-25
CVE-2016-6709 [MEDIUM] CWE-200 CVE-2016-6709: An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission.
nvd
CVE-2017-13183P4HIGHCVSS 7.0v8.12018-01-12
CVE-2017-13183 [HIGH] CWE-362 CVE-2017-13183: In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free
In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interac
nvd
CVE-2018-9508P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-10-02
CVE-2018-9508 [MEDIUM] CWE-125 CVE-2018-9508: In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an
In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2
nvd
CVE-2018-9507P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9507 [MEDIUM] CWE-125 CVE-2018-9507: In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect
In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.
nvd