Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 42 of 48
CVE-2017-0392P4MEDIUMCVSS 5.5vAndroid-7.0vAndroid-7.1.12017-01-12
CVE-2017-0392 [MEDIUM] CVE-2017-0392: A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a
A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.
nvd
CVE-2017-0643P4MEDIUMCVSS 5.5vAndroid-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.12017-06-14
CVE-2017-0643 [MEDIUM] CVE-2017-0643: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-35645051.
nvd
CVE-2017-0425P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0425 [MEDIUM] CWE-200 CVE-2017-0425: An information disclosure vulnerability in Audioserver could enable a local malicious application to
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32720785.
nvd
CVE-2017-0738P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-08-09
CVE-2017-0738 [MEDIUM] CWE-200 CVE-2017-0738: A information disclosure vulnerability in the Android media framework (audioserver). Product: Androi
A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.
nvd
CVE-2017-0815P4MEDIUMCVSS 5.5v4.4.4v5.0.2+7 more2017-10-04
CVE-2017-0815 [MEDIUM] CWE-200 CVE-2017-0815: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.
nvd
CVE-2017-0816P4MEDIUMCVSS 5.5v4.4.4v5.0.2+7 more2017-10-04
CVE-2017-0816 [MEDIUM] CWE-200 CVE-2017-0816: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63662938.
nvd
CVE-2017-0397P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0397 [MEDIUM] CWE-200 CVE-2017-0397: An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.
nvd
CVE-2017-0647P4MEDIUMCVSS 5.5vAndroid-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0647 [MEDIUM] CWE-200 CVE-2017-0647: An information disclosure vulnerability in libziparchive could enable a local malicious application
An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36392138.
nvd
CVE-2017-0635P4MEDIUMCVSS 5.5v7.0v7.1.1+1 more2017-05-12
CVE-2017-0635 [MEDIUM] CWE-476 CVE-2017-0635: A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could ena
A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35467107.
nvd
CVE-2016-6773P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+1 more2017-01-12
CVE-2016-6773 [MEDIUM] CWE-200 CVE-2016-6773: An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local ma
An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-30481714.
nvd
CVE-2017-0600P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0600 [MEDIUM] CVE-2017-0600: A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker t
A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35269635.
nvd
CVE-2017-0495P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0495 [MEDIUM] CWE-200 CVE-2017-0495: An information disclosure vulnerability in Mediaserver could enable a local malicious application to
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33552073.
nvd
CVE-2017-0529P4MEDIUMCVSS 5.5vn/a2017-03-08
CVE-2017-0529 [MEDIUM] CWE-200 CVE-2017-0529: An information disclosure vulnerability in the MediaTek driver could enable a local malicious applic
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-28449427. References: M-ALPS02710042.
nvd
CVE-2017-0602P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0602 [MEDIUM] CWE-200 CVE-2017-0602: An information disclosure vulnerability in Bluetooth could allow a local malicious application to by
An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Androi
nvd
CVE-2017-0601P4MEDIUMCVSS 5.5v7.0v7.1.1+1 more2017-05-12
CVE-2017-0601 [MEDIUM] CWE-732 CVE-2017-0601: An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious appl
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.
nvd
CVE-2017-0491P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0491 [MEDIUM] CVE-2017-0491: An elevation of privilege vulnerability in Package Manager could enable a local malicious applicatio
An elevation of privilege vulnerability in Package Manager could enable a local malicious application to prevent users from uninstalling applications or removing permissions from applications. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1.
nvd
CVE-2016-8396P4MEDIUMCVSS 5.5vn/a2017-01-12
CVE-2016-8396 [MEDIUM] CWE-200 CVE-2016-8396: An information disclosure vulnerability in the MediaTek video driver could enable a local malicious
An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-31249105.
nvd
CVE-2016-6771P4MEDIUMCVSS 5.3vAndroid-6.0vAndroid-6.0.1+1 more2017-01-12
CVE-2016-6771 [MEDIUM] CWE-284 CVE-2016-6771: An elevation of privilege vulnerability in Telephony could enable a local malicious application to a
An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-31566390.
nvd
CVE-2017-0627P4MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-05-12
CVE-2017-0627 [MEDIUM] CWE-200 CVE-2017-0627: An information disclosure vulnerability in the kernel UVC driver could enable a local malicious appl
An information disclosure vulnerability in the kernel UVC driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33300353.
nvd
CVE-2017-0630P4MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-05-12
CVE-2017-0630 [MEDIUM] CWE-200 CVE-2017-0630: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
nvd