Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
0
Severity breakdown
CRITICAL70HIGH618MEDIUM267LOW4
Vulnerabilities
Page 39 of 48
CVE-2017-0450HIGHCVSS 7.8vn/a2017-02-08
CVE-2017-0450 [HIGH] CVE-2017-0450: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.
nvd
CVE-2017-0440HIGHCVSS 7.0vKernel-3.10vKernel-3.182017-02-08
CVE-2017-0440 [HIGH] CWE-120 CVE-2017-0440: An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33252788. References: QC-CR
nvd
CVE-2017-0418HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0418 [HIGH] CWE-787 CVE-2017-0418: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0445HIGHCVSS 7.0vKernel-3.182017-02-08
CVE-2017-0445 [HIGH] CVE-2017-0445: An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32769717.
nvd
CVE-2017-0407HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0407 [HIGH] CWE-119 CVE-2017-0407: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. V
nvd
CVE-2017-0428HIGHCVSS 7.8vKernel-3.102017-02-08
CVE-2017-0428 [HIGH] CWE-416 CVE-2017-0428: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0416HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0416 [HIGH] CWE-787 CVE-2017-0416: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0430HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-02-08
CVE-2017-0430 [HIGH] CVE-2017-0430: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Version
nvd
CVE-2017-0448MEDIUMCVSS 5.5vKernel-3.102017-02-08
CVE-2017-0448 [MEDIUM] CWE-200 CVE-2017-0448: An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious ap
An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-32721029. References: N-CVE
nvd
CVE-2017-0423MEDIUMCVSS 5.3vAndroid-5.0.2vAndroid-5.1.1+4 more2017-02-08
CVE-2017-0423 [MEDIUM] CWE-732 CVE-2017-0423: An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage acc
An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586.
nvd
CVE-2017-0426MEDIUMCVSS 5.5vAndroid-7.0vAndroid-7.1.12017-02-08
CVE-2017-0426 [MEDIUM] CWE-200 CVE-2017-0426: An information disclosure vulnerability in the Filesystem could enable a local malicious application
An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32799236.
nvd
CVE-2017-0421MEDIUMCVSS 5.5vAndroid-5.0.2vAndroid-5.1.1+4 more2017-02-08
CVE-2017-0421 [MEDIUM] CWE-200 CVE-2017-0421: An information disclosure vulnerability in the Framework APIs could enable a local malicious applica
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 5.0.
nvd
CVE-2017-0424MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0424 [MEDIUM] CWE-200 CVE-2017-0424: An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a spe
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense in depth or exploit mitigation technology in a privileged process. Product: Android. Versions: 6.0
nvd
CVE-2017-0414MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0414 [MEDIUM] CWE-200 CVE-2017-0414: An information disclosure vulnerability in AOSP Messaging could enable a local malicious application
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0
nvd
CVE-2016-8414MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-02-08
CVE-2016-8414 [MEDIUM] CWE-200 CVE-2016-8414: An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator co
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31
nvd
CVE-2017-0420MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0420 [MEDIUM] CWE-200 CVE-2017-0420: An information disclosure vulnerability in AOSP Mail could enable a local malicious application to b
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2,
nvd
CVE-2017-0451MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-02-08
CVE-2017-0451 [MEDIUM] CWE-200 CVE-2017-0451: An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious
An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31796345. References: QC-CR#1073
nvd
CVE-2017-0425MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0425 [MEDIUM] CWE-200 CVE-2017-0425: An information disclosure vulnerability in Audioserver could enable a local malicious application to
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32720785.
nvd
CVE-2017-0413MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0413 [MEDIUM] CWE-200 CVE-2017-0413: An information disclosure vulnerability in AOSP Messaging could enable a local malicious application
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0
nvd
CVE-2016-8411CRITICALCVSS 9.8vversions that have i_qos_srvc.c2017-01-27
CVE-2016-8411 [CRITICAL] CWE-119 CVE-2016-8411: Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions th
Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775.
nvd