Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 6 of 48
CVE-2017-0855P3HIGHCVSS 7.5v5.1.1v6.0+5 more2018-01-12
CVE-2017-0855 [HIGH] CWE-772 CVE-2017-0855: In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up int
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.
nvd
CVE-2017-13192P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13192 [HIGH] CWE-835 CVE-2017-13192: In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero aft
In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite loop. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:
nvd
CVE-2017-13195P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13195 [HIGH] CWE-835 CVE-2017-13195: In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negati
In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes which could lead to an infinite loop. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Pro
nvd
CVE-2018-9359P3HIGHCVSS 7.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9359 [HIGH] CWE-125 CVE-2018-9359: In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds
In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.
nvd
CVE-2018-9361P3HIGHCVSS 7.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9361 [HIGH] CWE-125 CVE-2018-9361: In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds
In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.
nvd
CVE-2018-9436P3HIGHCVSS 7.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9436 [HIGH] CWE-125 CVE-2018-9436: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0
nvd
CVE-2018-9358P3HIGHCVSS 7.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9358 [HIGH] CWE-125 CVE-2018-9358: In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to
In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-
nvd
CVE-2018-9448P3HIGHCVSS 7.5vAndroid-8.0 Android-8.12018-11-06
CVE-2018-9448 [HIGH] CWE-125 CVE-2018-9448: In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing boun
In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-79944113.
nvd
CVE-2017-13259P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-04-04
CVE-2017-13259 [HIGH] CWE-125 CVE-2017-13259: In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to miss
In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID:
nvd
CVE-2017-0406P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0406 [HIGH] CWE-119 CVE-2017-0406: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. V
nvd
CVE-2017-0407P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0407 [HIGH] CWE-119 CVE-2017-0407: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. V
nvd
CVE-2017-0648P3HIGHCVSS 7.8vKernel-3.102017-06-14
CVE-2017-0648 [HIGH] CVE-2017-0648: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious ap
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Ke
nvd
CVE-2017-0510P3HIGHCVSS 7.8vKernel-3.102017-03-08
CVE-2017-0510 [HIGH] CVE-2017-0510: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious ap
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions
nvd
CVE-2017-0508P3HIGHCVSS 7.8vKernel-3.182017-03-08
CVE-2017-0508 [HIGH] CVE-2017-0508: An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious a
An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Version
nvd
CVE-2017-0507P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-03-08
CVE-2017-0507 [HIGH] CVE-2017-0507: An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious a
An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Version
nvd
CVE-2016-6777P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-6777 [HIGH] CWE-284 CVE-2016-6777: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-6776P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-6776 [HIGH] CWE-284 CVE-2016-6776: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-6775P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-6775 [HIGH] CWE-284 CVE-2016-6775: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8430P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8430 [HIGH] CWE-264 CVE-2016-8430: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0543P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-04-07
CVE-2017-0543 [HIGH] CWE-119 CVE-2017-0543: A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a spec
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0
nvd