cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 42 of 48
CVE-2017-0392P4MEDIUMCVSS 5.5vAndroid-7.0vAndroid-7.1.12017-01-12
CVE-2017-0392 [MEDIUM] CVE-2017-0392: A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.
nvd
CVE-2017-0643P4MEDIUMCVSS 5.5vAndroid-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.12017-06-14
CVE-2017-0643 [MEDIUM] CVE-2017-0643: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-35645051.
nvd
CVE-2017-0425P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-02-08
CVE-2017-0425 [MEDIUM] CWE-200 CVE-2017-0425: An information disclosure vulnerability in Audioserver could enable a local malicious application to An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32720785.
nvd
CVE-2017-0738P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-08-09
CVE-2017-0738 [MEDIUM] CWE-200 CVE-2017-0738: A information disclosure vulnerability in the Android media framework (audioserver). Product: Androi A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.
nvd
CVE-2017-0815P4MEDIUMCVSS 5.5v4.4.4v5.0.2+7 more2017-10-04
CVE-2017-0815 [MEDIUM] CWE-200 CVE-2017-0815: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.
nvd
CVE-2017-0816P4MEDIUMCVSS 5.5v4.4.4v5.0.2+7 more2017-10-04
CVE-2017-0816 [MEDIUM] CWE-200 CVE-2017-0816: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63662938.
nvd
CVE-2017-0397P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-01-12
CVE-2017-0397 [MEDIUM] CWE-200 CVE-2017-0397: An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.
nvd
CVE-2017-0647P4MEDIUMCVSS 5.5vAndroid-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0647 [MEDIUM] CWE-200 CVE-2017-0647: An information disclosure vulnerability in libziparchive could enable a local malicious application An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36392138.
nvd
CVE-2017-0635P4MEDIUMCVSS 5.5v7.0v7.1.1+1 more2017-05-12
CVE-2017-0635 [MEDIUM] CWE-476 CVE-2017-0635: A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could ena A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35467107.
nvd
CVE-2016-6773P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+1 more2017-01-12
CVE-2016-6773 [MEDIUM] CWE-200 CVE-2016-6773: An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local ma An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-30481714.
nvd
CVE-2017-0600P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0600 [MEDIUM] CVE-2017-0600: A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker t A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35269635.
nvd
CVE-2017-0495P4MEDIUMCVSS 5.5vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0495 [MEDIUM] CWE-200 CVE-2017-0495: An information disclosure vulnerability in Mediaserver could enable a local malicious application to An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33552073.
nvd
CVE-2017-0529P4MEDIUMCVSS 5.5vn/a2017-03-08
CVE-2017-0529 [MEDIUM] CWE-200 CVE-2017-0529: An information disclosure vulnerability in the MediaTek driver could enable a local malicious applic An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-28449427. References: M-ALPS02710042.
nvd
CVE-2017-0602P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-05-12
CVE-2017-0602 [MEDIUM] CWE-200 CVE-2017-0602: An information disclosure vulnerability in Bluetooth could allow a local malicious application to by An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Androi
nvd
CVE-2017-0601P4MEDIUMCVSS 5.5v7.0v7.1.1+1 more2017-05-12
CVE-2017-0601 [MEDIUM] CWE-732 CVE-2017-0601: An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious appl An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.
nvd
CVE-2017-0491P4MEDIUMCVSS 5.5vAndroid-4.4.4vAndroid-5.0.2+5 more2017-03-08
CVE-2017-0491 [MEDIUM] CVE-2017-0491: An elevation of privilege vulnerability in Package Manager could enable a local malicious applicatio An elevation of privilege vulnerability in Package Manager could enable a local malicious application to prevent users from uninstalling applications or removing permissions from applications. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1.
nvd
CVE-2016-8396P4MEDIUMCVSS 5.5vn/a2017-01-12
CVE-2016-8396 [MEDIUM] CWE-200 CVE-2016-8396: An information disclosure vulnerability in the MediaTek video driver could enable a local malicious An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-31249105.
nvd
CVE-2016-6771P4MEDIUMCVSS 5.3vAndroid-6.0vAndroid-6.0.1+1 more2017-01-12
CVE-2016-6771 [MEDIUM] CWE-284 CVE-2016-6771: An elevation of privilege vulnerability in Telephony could enable a local malicious application to a An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-31566390.
nvd
CVE-2017-0627P4MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-05-12
CVE-2017-0627 [MEDIUM] CWE-200 CVE-2017-0627: An information disclosure vulnerability in the kernel UVC driver could enable a local malicious appl An information disclosure vulnerability in the kernel UVC driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33300353.
nvd
CVE-2017-0630P4MEDIUMCVSS 4.7vKernel-3.10vKernel-3.182017-05-12
CVE-2017-0630 [MEDIUM] CWE-200 CVE-2017-0630: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
nvd
Google Inc Android vulnerabilities | cvebase