cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 5 of 48
CVE-2018-9496P3HIGHCVSS 7.8vAndroid-9.02018-10-02
CVE-2018-9496 [HIGH] CWE-787 CVE-2018-9496: In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-110769924
nvd
CVE-2018-9497P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.02018-10-02
CVE-2018-9497 [HIGH] CWE-787 CVE-2018-9497: In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bou In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 And
nvd
CVE-2016-8398P3CRITICALCVSS 9.8vKernel-3.102017-01-12
CVE-2016-8398 [CRITICAL] CWE-254 CVE-2016-8398: Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS securit Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.
nvd
CVE-2017-0786P3HIGHCVSS 8.8vAndroid kernel2017-09-08
CVE-2017-0786 [HIGH] CVE-2017-0786: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.
nvd
CVE-2017-0787P3HIGHCVSS 8.8vAndroid kernel2017-09-08
CVE-2017-0787 [HIGH] CVE-2017-0787: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722970. References: B-V2017053104.
nvd
CVE-2017-0789P3HIGHCVSS 8.8vAndroid kernel2017-09-08
CVE-2017-0789 [HIGH] CVE-2017-0789: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37685267. References: B-V2017053102.
nvd
CVE-2017-0790P3HIGHCVSS 8.8vAndroid kernel2017-09-08
CVE-2017-0790 [HIGH] CVE-2017-0790: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37357704. References: B-V2017053101.
nvd
CVE-2017-0791P3HIGHCVSS 8.8vAndroid kernel2017-09-08
CVE-2017-0791 [HIGH] CVE-2017-0791: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37306719. References: B-V2017052302.
nvd
CVE-2017-0788P3HIGHCVSS 8.8vAndroid kernel2017-09-08
CVE-2017-0788 [HIGH] CVE-2017-0788: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722328. References: B-V2017053103.
nvd
CVE-2017-0540P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+4 more2017-04-07
CVE-2017-0540 [HIGH] CWE-119 CVE-2017-0540: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0663P3HIGHCVSS 7.8vAndroid-4.4.4 Android-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0663 [HIGH] CWE-787 CVE-2017-0663: A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1,
nvd
CVE-2017-0474P3HIGHCVSS 7.8vAndroid-7.0vAndroid-7.1.12017-03-08
CVE-2017-0474 [HIGH] CWE-119 CVE-2017-0474: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 7.0, 7.1.1. Android ID: A
nvd
CVE-2018-9363P3HIGHCVSS 8.4vAndroid kernel2018-11-06
CVE-2018-9363 [HIGH] CWE-190 CVE-2018-9363: In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.
nvd
CVE-2018-9427P3HIGHCVSS 7.8vAndroid-8.0 Android-8.12018-11-06
CVE-2018-9427 [HIGH] CWE-787 CVE-2018-9427: In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect boun In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-77486542.
nvd
CVE-2017-0478P3HIGHCVSS 7.8vAndroid-5.0.2vAndroid-5.1.1+4 more2017-03-08
CVE-2017-0478 [HIGH] CVE-2017-0478: A remote code execution vulnerability in the Framesequence library could enable an attacker using a A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0405P3HIGHCVSS 7.8vAndroid-7.0vAndroid-7.1.12017-02-08
CVE-2017-0405 [HIGH] CWE-119 CVE-2017-0405: A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially c A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Surfaceflinger process. Product: Android. Versions: 7.0, 7.1.1. Android
nvd
CVE-2018-9498P3HIGHCVSS 7.8vAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-10-02
CVE-2018-9498 [HIGH] CWE-190 CVE-2018-9498: In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overf In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78354855
nvd
CVE-2017-13199P3HIGHCVSS 7.5v8.0v8.12018-01-12
CVE-2017-13199 [HIGH] CWE-755 CVE-2017-13199: In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a jav In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-33
nvd
CVE-2017-13196P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13196 [HIGH] CWE-772 CVE-2017-13196: In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could l In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could lead to memory leaks. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7
nvd
CVE-2017-13193P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13193 [HIGH] CWE-835 CVE-2017-13193: In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resoluti In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over and over. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versio
nvd
Google Inc Android vulnerabilities | cvebase