cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 39 of 48
CVE-2017-0401P4MEDIUMCVSS 5.5vAndroid-5.0.2vAndroid-5.1.1+4 more2017-01-12
CVE-2017-0401 [MEDIUM] CWE-200 CVE-2017-0401: An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.
nvd
CVE-2017-0399P4MEDIUMCVSS 5.5vAndroid-5.0.2vAndroid-5.1.1+4 more2017-01-12
CVE-2017-0399 [MEDIUM] CWE-200 CVE-2017-0399: An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.
nvd
CVE-2017-0639P4MEDIUMCVSS 5.5vAndroid-4.4.4 Android-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0639 [MEDIUM] CWE-200 CVE-2017-0639: An information disclosure vulnerability in Bluetooth component could enable a local malicious applic An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.
nvd
CVE-2017-0646P4MEDIUMCVSS 5.5vAndroid-4.4.4 Android-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0646 [MEDIUM] CWE-200 CVE-2017-0646: An information disclosure vulnerability in Bluetooth component could enable a local malicious applic An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33899337.
nvd
CVE-2017-0645P4MEDIUMCVSS 5.5vAndroid-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0645 [MEDIUM] CWE-200 CVE-2017-0645: An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to a An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35385327.
nvd
CVE-2017-0598P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0598 [MEDIUM] CWE-200 CVE-2017-0598: An information disclosure vulnerability in the Framework APIs could enable a local malicious applica An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.
nvd
CVE-2016-6698P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6698 [MEDIUM] CWE-200 CVE-2016-6698: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6750P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6750 [MEDIUM] CWE-200 CVE-2016-6750: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6721P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+1 more2016-11-25
CVE-2016-6721 [MEDIUM] CWE-200 CVE-2016-6721: An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 befo An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-30875060.
nvd
CVE-2016-6718P4MEDIUMCVSS 5.5vAndroid-7.02016-11-25
CVE-2016-6718 [MEDIUM] CWE-200 CVE-2016-6718: An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11 An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to retrieve sensitive information without user interaction. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require
nvd
CVE-2017-0793P4MEDIUMCVSS 5.5vAndroid kernel2017-09-08
CVE-2017-0793 [MEDIUM] CWE-200 CVE-2017-0793: A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Andr A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.
nvd
CVE-2017-0489P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0489 [MEDIUM] CVE-2017-0489: An elevation of privilege vulnerability in Location Manager could enable a local malicious applicati An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33091107.
nvd
CVE-2016-6748P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6748 [MEDIUM] CWE-200 CVE-2016-6748: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6752P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6752 [MEDIUM] CWE-200 CVE-2016-6752: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6749P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6749 [MEDIUM] CWE-200 CVE-2016-6749: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6751P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-6751 [MEDIUM] CWE-200 CVE-2016-6751: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-3907P4MEDIUMCVSS 5.5vKernel-3.10vKernel-3.182016-11-25
CVE-2016-3907 [MEDIUM] CWE-200 CVE-2016-3907: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2017-0493P4MEDIUMCVSS 5.5v7.0v7.1.12017-05-12
CVE-2017-0493 [MEDIUM] CWE-922 CVE-2017-0493: An information disclosure vulnerability in File-Based Encryption could enable a local malicious atta An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32793550.
nvd
CVE-2016-8462P4MEDIUMCVSS 5.5vn/a2017-01-12
CVE-2016-8462 [MEDIUM] CWE-200 CVE-2016-8462: An information disclosure vulnerability in the bootloader could enable a local attacker to access da An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: N/A. Android ID: A-32510383.
nvd
CVE-2018-9511P4MEDIUMCVSS 5.5vAndroid-9.02018-10-02
CVE-2018-9511 [MEDIUM] CWE-909 CVE-2018-9511: In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a secur In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a security feature due to uninitialized data. This could lead to local denial of service of IPsec on sockets with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-1
nvd
Google Inc Android vulnerabilities | cvebase