cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 41 of 48
CVE-2017-0396P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0396 [MEDIUM] CWE-200 CVE-2017-0396: An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaser An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6
nvd
CVE-2017-0490P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0490 [MEDIUM] CVE-2017-0490: An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delet An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delete user data. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33178389.
nvd
CVE-2017-0708P4MEDIUMCVSS 5.5vAndroid kernel2017-07-06
CVE-2017-0708 [MEDIUM] CWE-200 CVE-2017-0708: A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.
nvd
CVE-2017-0492P4MEDIUMCVSS 5.5vAndroid-7.1.12017-03-08
CVE-2017-0492 [MEDIUM] CWE-1021 CVE-2017-0492: An elevation of privilege vulnerability in the System UI could enable a local malicious application An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission. Product: Android. Versions: 7.1.1. An
nvd
CVE-2016-6715P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+4 more2016-11-25
CVE-2016-6715 [MEDIUM] CWE-275 CVE-2016-6715: An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x bef An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the user's permission. This issue is rated as Moderate because it is a local bypass of user interaction req
nvd
CVE-2017-0625P4MEDIUMCVSS 5.5vn/a2017-05-12
CVE-2017-0625 [MEDIUM] CWE-200 CVE-2017-0625: An information disclosure vulnerability in the MediaTek command queue driver could enable a local ma An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-35142799. References: M-A
nvd
CVE-2016-6719P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+4 more2016-11-25
CVE-2016-6719 [MEDIUM] CWE-275 CVE-2016-6719: An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0. An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair with any Bluetooth device without user consent. This issue is rated as Moderate because it is a local bypass of user
nvd
CVE-2016-6716P4MEDIUMCVSS 5.5vAndroid-7.02016-11-25
CVE-2016-6716 [MEDIUM] CWE-284 CVE-2016-6716: An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally r
nvd
CVE-2017-0395P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0395 [MEDIUM] CVE-2017-0395: An elevation of privilege vulnerability in Contacts could enable a local malicious application to si An elevation of privilege vulnerability in Contacts could enable a local malicious application to silently create contact information. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Product: Android. Versions: 4.4.4,
nvd
CVE-2017-13275P4MEDIUMCVSS 5.5v8.0v8.12018-04-04
CVE-2017-13275 [MEDIUM] CWE-125 CVE-2017-13275: In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bou In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-70808908.
nvd
CVE-2016-8405P4MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-01-12
CVE-2016-8405 [MEDIUM] CWE-200 CVE-2016-8405: An information disclosure vulnerability in kernel components including the ION subsystem, Binder, US An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel
nvd
CVE-2017-0393P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0393 [MEDIUM] CVE-2017-0393: A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a s A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.
nvd
CVE-2017-0548P4MEDIUMCVSS 5.5vAndroid-7.0vAndroid-7.1.12017-04-07
CVE-2017-0548 [MEDIUM] CWE-119 CVE-2017-0548: A remote denial of service vulnerability in libskia could enable an attacker to use a specially craf A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33251605.
nvd
CVE-2017-0642P4MEDIUMCVSS 5.5vAndroid-5.0.2 Android-5.1.12017-06-14
CVE-2017-0642 [MEDIUM] CVE-2017-0642: A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34819017.
nvd
CVE-2017-0549P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-04-07
CVE-2017-0549 [MEDIUM] CVE-2017-0549: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818508.
nvd
CVE-2017-0552P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-04-07
CVE-2017-0552 [MEDIUM] CVE-2017-0552: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097915.
nvd
CVE-2017-0550P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-04-07
CVE-2017-0550 [MEDIUM] CVE-2017-0550: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33933140.
nvd
CVE-2017-0599P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-05-12
CVE-2017-0599 [MEDIUM] CWE-252 CVE-2017-0599: A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34672748.
nvd
CVE-2017-0391P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-01-12
CVE-2017-0391 [MEDIUM] CVE-2017-0391: A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32322258.
nvd
CVE-2017-0390P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0390 [MEDIUM] CVE-2017-0390: A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31647370.
nvd
Google Inc Android vulnerabilities | cvebase