cbcvebase.

Google Inc Android vulnerabilities

959 known vulnerabilities affecting google_inc/android.

Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4

Vulnerabilities

Page 8 of 48
CVE-2018-9516P3HIGHCVSS 7.8vAndroid kernel2018-11-06
CVE-2018-9516 [HIGH] CWE-787 CVE-2018-9516: In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-71361580.
nvd
CVE-2016-8411P3CRITICALCVSS 9.8vversions that have i_qos_srvc.c2017-01-27
CVE-2016-8411 [CRITICAL] CWE-119 CVE-2016-8411: Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions th Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775.
nvd
CVE-2017-0784P3HIGHCVSS 8.8v5.0.2v5.1.1+5 more2017-09-08
CVE-2017-0784 [HIGH] CWE-732 CVE-2017-0784: A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0. A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.
nvd
CVE-2017-0810P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-10-04
CVE-2017-0810 [HIGH] CWE-119 CVE-2017-0810: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38207066.
nvd
CVE-2017-0811P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-10-04
CVE-2017-0811 [HIGH] CVE-2017-0811: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37930177.
nvd
CVE-2016-8428P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8428 [HIGH] CWE-264 CVE-2016-8428: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8426P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8426 [HIGH] CWE-264 CVE-2016-8426: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8427P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8427 [HIGH] CWE-264 CVE-2016-8427: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8425P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8425 [HIGH] CWE-264 CVE-2016-8425: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8429P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8429 [HIGH] CWE-264 CVE-2016-8429: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8479P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-03-08
CVE-2016-8479 [HIGH] CWE-264 CVE-2016-8479: An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-8431P3HIGHCVSS 7.8vKernel-3.182017-01-12
CVE-2016-8431 [HIGH] CWE-264 CVE-2016-8431: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8432P3HIGHCVSS 7.8vKernel-3.182017-01-12
CVE-2016-8432 [HIGH] CWE-264 CVE-2016-8432: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0809P3HIGHCVSS 7.8v4.4.4v5.0.2+7 more2017-10-04
CVE-2017-0809 [HIGH] CWE-119 CVE-2017-0809: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673128.
nvd
CVE-2017-0637P3HIGHCVSS 7.8vAndroid-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0637 [HIGH] CWE-119 CVE-2017-0637: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process.Product: Android. Versions: 5.0.2, 5.1.1, 6
nvd
CVE-2017-13214P3HIGHCVSS 7.5vAndroid kernel2018-01-12
CVE-2017-13214 [HIGH] CWE-20 CVE-2017-13214: In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38495900.
nvd
CVE-2017-0471P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0471 [HIGH] CWE-119 CVE-2017-0471: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0469P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0469 [HIGH] CWE-119 CVE-2017-0469: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0466P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0466 [HIGH] CWE-119 CVE-2017-0466: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0468P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0468 [HIGH] CWE-119 CVE-2017-0468: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
Google Inc Android vulnerabilities | cvebase