cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 36 of 48
CVE-2018-9505P4MEDIUMCVSS 6.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9505 [MEDIUM] CWE-125 CVE-2018-9505: In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds ch In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-
nvd
CVE-2017-13305P4HIGHCVSS 7.1vAndroid kernel2018-04-04
CVE-2017-13305 [HIGH] CWE-125 CVE-2017-13305: A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Vers A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
nvd
CVE-2018-9493P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9493 [MEDIUM] CWE-89 CVE-2018-9493: In the content provider of the download manager, there is a possible SQL injection due to improper i In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 A
nvd
CVE-2017-0705P4MEDIUMCVSS 6.8vAndroid kernel2017-07-06
CVE-2017-0705 [MEDIUM] CVE-2017-0705: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.
nvd
CVE-2017-0706P4MEDIUMCVSS 6.8vAndroid kernel2017-07-06
CVE-2017-0706 [MEDIUM] CWE-119 CVE-2017-0706: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532.
nvd
CVE-2017-13235P4MEDIUMCVSS 6.5v7.0v7.1.1+3 more2018-02-12
CVE-2017-13235 [MEDIUM] CWE-476 CVE-2017-13235: A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866.
nvd
CVE-2018-9519P4MEDIUMCVSS 6.4vAndroid Kernel2018-12-07
CVE-2018-9519 [MEDIUM] CWE-362 CVE-2018-9519: In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-69808833.
nvd
CVE-2017-0792P4MEDIUMCVSS 6.5vAndroid kernel2017-09-08
CVE-2017-0792 [MEDIUM] CWE-200 CVE-2017-0792: A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.
nvd
CVE-2016-8467P4MEDIUMCVSS 5.5vn/a2017-01-13
CVE-2016-8467 [MEDIUM] CWE-264 CVE-2016-8467: An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute a An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely permanent or requiring re-flashing the entire operating system). Product: Android. Versions: N/A. A
nvd
CVE-2018-9499P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9499 [MEDIUM] CWE-908 CVE-2018-9499: In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local information disclosure from the DRM server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android
nvd
CVE-2017-0880P4MEDIUMCVSS 6.5v7.0v7.1.1+1 more2017-12-06
CVE-2017-0880 [MEDIUM] CVE-2017-0880: A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versio A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID A-65646012.
nvd
CVE-2017-13148P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2017-12-06
CVE-2017-13148 [MEDIUM] CWE-20 CVE-2017-13148: A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versi A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65717533.
nvd
CVE-2017-0874P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2017-12-06
CVE-2017-0874 [MEDIUM] CWE-20 CVE-2017-0874: A denial of service vulnerability in the Android media framework (libavc). Product: Android. Version A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63315932.
nvd
CVE-2017-0873P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2017-12-06
CVE-2017-0873 [MEDIUM] CWE-20 CVE-2017-0873: A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versi A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63316255.
nvd
CVE-2017-0783P4MEDIUMCVSS 6.5v4.4.4v5.0.2+7 more2017-09-14
CVE-2017-0783 [MEDIUM] CWE-200 CVE-2017-0783: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.
nvd
CVE-2017-13290P4MEDIUMCVSS 6.2v6.0v6.0.1+5 more2018-04-04
CVE-2017-13290 [MEDIUM] CWE-125 CVE-2017-13290: In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bo In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69384124.
nvd
CVE-2016-8397P4MEDIUMCVSS 5.5vKernel-3.102017-01-12
CVE-2016-8397 [MEDIUM] CWE-200 CVE-2016-8397: An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious ap An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-31385953. References: N-CVE
nvd
CVE-2016-8400P4MEDIUMCVSS 5.5vKernel-3.182017-01-12
CVE-2016-8400 [MEDIUM] CWE-200 CVE-2016-8400: An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local m An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CV
nvd
CVE-2018-9566P4MEDIUMCVSS 5.7vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9566 [MEDIUM] CWE-125 CVE-2018-9566: In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a mi In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure when connecting to a malicious Bluetooth device with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 And
nvd
CVE-2017-0424P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0424 [MEDIUM] CWE-200 CVE-2017-0424: An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a spe An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense in depth or exploit mitigation technology in a privileged process. Product: Android. Versions: 6.0
nvd
Google Inc Android vulnerabilities | cvebase