Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 4 of 48
CVE-2018-9530P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9530 [HIGH] CWE-787 CVE-2018-9530: In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a
In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112609715
nvd
CVE-2017-13256P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-04-04
CVE-2017-13256 [HIGH] CWE-787 CVE-2017-13256: In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missin
In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68817966.
nvd
CVE-2017-13274P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13274 [CRITICAL] CWE-346 CVE-2017-13274: In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determin
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71360761.
nvd
CVE-2018-9571P3HIGHCVSS 8.8vAndroid-92018-12-07
CVE-2018-9571 [HIGH] CWE-787 CVE-2018-9571: In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound wr
In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116020594.
nvd
CVE-2018-9569P3HIGHCVSS 8.8vAndroid-92018-12-07
CVE-2018-9569 [HIGH] CWE-787 CVE-2018-9569: In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound writ
In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113885537.
nvd
CVE-2018-9533P3HIGHCVSS 8.8vAndroid-92018-11-14
CVE-2018-9533 [HIGH] CWE-119 CVE-2018-9533: In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missin
In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112766520
nvd
CVE-2016-8438P3CRITICALCVSS 9.8vKernel-3.182017-01-12
CVE-2016-8438 [CRITICAL] CWE-190 CVE-2016-8438: Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race
Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
nvd
CVE-2016-8459P3CRITICALCVSS 9.8vKernel-3.182017-01-12
CVE-2016-8459 [CRITICAL] CWE-119 CVE-2016-8459: Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB
Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577972. References: QC-CR#988462.
nvd
CVE-2016-8437P3CRITICALCVSS 9.8vKernel-3.182017-01-12
CVE-2016-8437 [CRITICAL] CWE-20 CVE-2016-8437: Improper input validation in Access Control APIs. Access control API may return memory range checkin
Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel 3.18. Android ID: A-31623057. References: QC-CR#1009695.
nvd
CVE-2017-0541P3HIGHCVSS 7.8vAndroid-4.4.4vAndroid-5.0.2+5 more2017-04-07
CVE-2017-0541 [HIGH] CWE-119 CVE-2017-0541: A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2,
nvd
CVE-2018-9459P3HIGHCVSS 8.8vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9459 [HIGH] CWE-22 CVE-2018-9459: In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible
In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal error. This could lead to a remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 A
nvd
CVE-2017-0877P3HIGHCVSS 8.8v6.02017-12-06
CVE-2017-0877 [HIGH] CWE-20 CVE-2017-0877: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.
nvd
CVE-2017-0878P3HIGHCVSS 8.8v8.02017-12-06
CVE-2017-0878 [HIGH] CWE-20 CVE-2017-0878: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291.
nvd
CVE-2017-0872P3HIGHCVSS 8.8v7.0v7.1.1+2 more2017-12-06
CVE-2017-0872 [HIGH] CWE-20 CVE-2017-0872: A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65290323.
nvd
CVE-2017-0876P3HIGHCVSS 8.8v6.02017-12-06
CVE-2017-0876 [HIGH] CWE-20 CVE-2017-0876: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675.
nvd
CVE-2017-13151P3HIGHCVSS 8.8v6.0v6.0.1+4 more2017-12-06
CVE-2017-13151 [HIGH] CWE-682 CVE-2017-13151: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63874456.
nvd
CVE-2017-13176P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13176 [HIGH] CWE-20 CVE-2017-13176: In the parseURL function of URLStreamHandler, there is improper input validation of the host field.
In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7
nvd
CVE-2018-9555P3HIGHCVSS 8.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-92018-12-06
CVE-2018-9555 [HIGH] CWE-787 CVE-2018-9555: In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds c
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2017-0807P3CRITICALCVSS 9.8v5.1.1v6.0+4 more2017-10-04
CVE-2017-0807 [CRITICAL] CVE-2017-0807: An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. V
An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.
nvd
CVE-2018-9503P3HIGHCVSS 7.5vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9503 [HIGH] CWE-125 CVE-2018-9503: In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missi
In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 A
nvd