Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 37 of 48
CVE-2018-9552P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9552 [MEDIUM] CWE-787 CVE-2018-9552: In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bound
In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Androi
nvd
CVE-2016-6710P4MEDIUMCVSS 5.5vAndroid-5.0.2vAndroid-5.1.1+3 more2016-11-25
CVE-2016-6710 [MEDIUM] CWE-200 CVE-2016-6710: An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x
An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used
nvd
CVE-2018-9454P4MEDIUMCVSS 5.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9454 [MEDIUM] CWE-125 CVE-2018-9454: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0
nvd
CVE-2018-9451P4MEDIUMCVSS 5.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9451 [MEDIUM] CWE-125 CVE-2018-9451: In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missi
In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.
nvd
CVE-2018-9453P4MEDIUMCVSS 5.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9453 [MEDIUM] CWE-125 CVE-2018-9453: In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds c
In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8
nvd
CVE-2018-9544P4MEDIUMCVSS 5.5vAndroid-92018-11-14
CVE-2018-9544 [MEDIUM] CWE-125 CVE-2018-9544: In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check.
In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113037220
nvd
CVE-2018-9548P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9548 [MEDIUM] CWE-862 CVE-2018-9548: In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missin
In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.
nvd
CVE-2017-0748P4MEDIUMCVSS 5.3vAndroid kernel2018-04-05
CVE-2017-0748 [MEDIUM] CWE-200 CVE-2017-0748: An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: An
An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.
nvd
CVE-2017-13304P4MEDIUMCVSS 5.3vAndroid kernel2018-04-04
CVE-2017-13304 [MEDIUM] CWE-200 CVE-2017-13304: A information disclosure vulnerability in the Upstream kernel mnh_sm driver. Product: Android. Versi
A information disclosure vulnerability in the Upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-70576999.
nvd
CVE-2017-13303P4MEDIUMCVSS 5.3vAndroid kernel2018-04-04
CVE-2017-13303 [MEDIUM] CWE-200 CVE-2017-13303: A information disclosure vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: An
A information disclosure vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-71359108. References: B-V2018010501.
nvd
CVE-2017-0744P4MEDIUMCVSS 5.3vAndroid kernel2018-04-05
CVE-2017-0744 [MEDIUM] CVE-2017-0744: An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Ve
An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Versions: Android kernel. Android ID: A-34112726. References: N-CVE-2017-0744.
nvd
CVE-2017-13165P4MEDIUMCVSS 5.3vAndroid kernel2017-12-06
CVE-2017-13165 [MEDIUM] CWE-269 CVE-2017-13165: An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Andro
An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.
nvd
CVE-2017-0860P4MEDIUMCVSS 5.3v5.0.2v5.1.1+5 more2017-11-16
CVE-2017-0860 [MEDIUM] CVE-2017-0860: An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. V
An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-31097064.
nvd
CVE-2017-0778P4HIGHCVSS 7.1v7.0v7.1.1+1 more2017-09-08
CVE-2017-0778 [HIGH] CWE-200 CVE-2017-0778: A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versi
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.
nvd
CVE-2017-0641P4MEDIUMCVSS 5.5vAndroid-4.4.4 Android-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0641 [MEDIUM] CWE-665 CVE-2017-0641: A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a
A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.
nvd
CVE-2016-8460P4MEDIUMCVSS 5.5vKernel-3.102017-01-12
CVE-2016-8460 [MEDIUM] CWE-200 CVE-2016-8460: An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious ap
An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-31668540. References: N-CVE
nvd
CVE-2017-0420P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0420 [MEDIUM] CWE-200 CVE-2017-0420: An information disclosure vulnerability in AOSP Mail could enable a local malicious application to b
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2,
nvd
CVE-2017-0413P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0413 [MEDIUM] CWE-200 CVE-2017-0413: An information disclosure vulnerability in AOSP Messaging could enable a local malicious application
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0
nvd
CVE-2017-0421P4MEDIUMCVSS 5.5vAndroid-5.0.2vAndroid-5.1.1+4 more2017-02-08
CVE-2017-0421 [MEDIUM] CWE-200 CVE-2017-0421: An information disclosure vulnerability in the Framework APIs could enable a local malicious applica
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 5.0.
nvd
CVE-2017-0448P4MEDIUMCVSS 5.5vKernel-3.102017-02-08
CVE-2017-0448 [MEDIUM] CWE-200 CVE-2017-0448: An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious ap
An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-32721029. References: N-CVE
nvd