Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 38 of 48
CVE-2017-0560P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-04-07
CVE-2017-0560 [MEDIUM] CWE-200 CVE-2017-0560: An information disclosure vulnerability in the factory reset process could enable a local malicious
An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing device protection. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-30681079.
nvd
CVE-2016-6746P4MEDIUMCVSS 5.5vKernel-3.182016-11-25
CVE-2016-6746 [MEDIUM] CWE-200 CVE-2016-6746: An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could
An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Android ID: A-30955105. References: NVIDIA N-CVE-2016-67
nvd
CVE-2018-9543P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-11-14
CVE-2018-9543 [MEDIUM] CWE-200 CVE-2018-9543: In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a
In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local information disclosure after factory reset with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2018-9554P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-12-06
CVE-2018-9554 [MEDIUM] CWE-200 CVE-2018-9554: In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media f
In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2018-9457P4MEDIUMCVSS 5.5vAndroid-8.0 Android-8.1 Android-92018-11-14
CVE-2018-9457 [MEDIUM] CWE-862 CVE-2018-9457: In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact
In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Andro
nvd
CVE-2017-0388P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-01-12
CVE-2017-0388 [MEDIUM] CWE-200 CVE-2017-0388: An elevation of privilege vulnerability in the External Storage Provider could enable a local second
An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Ver
nvd
CVE-2017-13294P4MEDIUMCVSS 5.3v6.0v6.0.1+5 more2018-04-04
CVE-2017-13294 [MEDIUM] CWE-200 CVE-2017-13294: A information disclosure vulnerability in the Android framework (aosp email application). Product: A
A information disclosure vulnerability in the Android framework (aosp email application). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71814449.
nvd
CVE-2017-0423P4MEDIUMCVSS 5.3vAndroid-5.0.2vAndroid-5.1.1+4 more2017-02-08
CVE-2017-0423 [MEDIUM] CWE-732 CVE-2017-0423: An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage acc
An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586.
nvd
CVE-2017-0751P4MEDIUMCVSS 5.3vAndroid kernel2018-04-05
CVE-2017-0751 [MEDIUM] CVE-2017-0751: An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Andr
An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Android kernel. Android ID: A-36591162. References: QC-CR#2045061.
nvd
CVE-2016-8463P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182017-01-12
CVE-2016-8463 [MEDIUM] CWE-399 CVE-2016-8463: A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to
A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-30786860. References: QC-CR#586855.
nvd
CVE-2017-0626P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182017-05-12
CVE-2017-0626 [MEDIUM] CWE-200 CVE-2017-0626: An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local ma
An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-3539
nvd
CVE-2017-0624P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182017-05-12
CVE-2017-0624 [MEDIUM] CWE-200 CVE-2017-0624: An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34327795. Ref
nvd
CVE-2016-8483P4MEDIUMCVSS 5.5vKernel-3.102017-03-08
CVE-2016-8483 [MEDIUM] CWE-200 CVE-2016-8483: An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious
An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-33745862. References: QC-C
nvd
CVE-2018-9437P4MEDIUMCVSS 5.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9437 [MEDIUM] CWE-125 CVE-2018-9437: In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This c
In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Andro
nvd
CVE-2017-0414P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0414 [MEDIUM] CWE-200 CVE-2017-0414: An information disclosure vulnerability in AOSP Messaging could enable a local malicious application
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0
nvd
CVE-2017-0494P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0494 [MEDIUM] CWE-200 CVE-2017-0494: An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a spe
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32764144.
nvd
CVE-2017-13279P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2018-04-04
CVE-2017-13279 [MEDIUM] CWE-834 CVE-2017-13279: In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of p
In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-683
nvd
CVE-2017-0547P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-04-07
CVE-2017-0547 [MEDIUM] CWE-200 CVE-2017-0547: An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious ap
An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
nvd
CVE-2017-0398P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-13
CVE-2017-0398 [MEDIUM] CWE-200 CVE-2017-0398: An information disclosure vulnerability in Audioserver could enable a local malicious application to
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android IDs: A-32438594, A-326356
nvd
CVE-2016-6753P4MEDIUMCVSS 5.5vKernel-3.182016-11-25
CVE-2016-6753 [MEDIUM] CWE-200 CVE-2016-6753: An information disclosure vulnerability in kernel components, including the process-grouping subsyst
An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Androi
nvd