Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 8 of 48
CVE-2018-9516P3HIGHCVSS 7.8vAndroid kernel2018-11-06
CVE-2018-9516 [HIGH] CWE-787 CVE-2018-9516: In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to
In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-71361580.
nvd
CVE-2016-8411P3CRITICALCVSS 9.8vversions that have i_qos_srvc.c2017-01-27
CVE-2016-8411 [CRITICAL] CWE-119 CVE-2016-8411: Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions th
Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775.
nvd
CVE-2017-0784P3HIGHCVSS 8.8v5.0.2v5.1.1+5 more2017-09-08
CVE-2017-0784 [HIGH] CWE-732 CVE-2017-0784: A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.
A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.
nvd
CVE-2017-0810P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-10-04
CVE-2017-0810 [HIGH] CWE-119 CVE-2017-0810: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38207066.
nvd
CVE-2017-0811P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-10-04
CVE-2017-0811 [HIGH] CVE-2017-0811: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37930177.
nvd
CVE-2016-8428P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8428 [HIGH] CWE-264 CVE-2016-8428: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8426P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8426 [HIGH] CWE-264 CVE-2016-8426: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8427P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8427 [HIGH] CWE-264 CVE-2016-8427: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8425P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8425 [HIGH] CWE-264 CVE-2016-8425: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8429P3HIGHCVSS 7.8vKernel-3.102017-01-12
CVE-2016-8429 [HIGH] CWE-264 CVE-2016-8429: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8479P3HIGHCVSS 7.8vKernel-3.10vKernel-3.182017-03-08
CVE-2016-8479 [HIGH] CWE-264 CVE-2016-8479: An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious ap
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-8431P3HIGHCVSS 7.8vKernel-3.182017-01-12
CVE-2016-8431 [HIGH] CWE-264 CVE-2016-8431: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2016-8432P3HIGHCVSS 7.8vKernel-3.182017-01-12
CVE-2016-8432 [HIGH] CWE-264 CVE-2016-8432: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0809P3HIGHCVSS 7.8v4.4.4v5.0.2+7 more2017-10-04
CVE-2017-0809 [HIGH] CWE-119 CVE-2017-0809: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673128.
nvd
CVE-2017-0637P3HIGHCVSS 7.8vAndroid-5.0.2 Android-5.1.1 Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.22017-06-14
CVE-2017-0637 [HIGH] CWE-119 CVE-2017-0637: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process.Product: Android. Versions: 5.0.2, 5.1.1, 6
nvd
CVE-2017-13214P3HIGHCVSS 7.5vAndroid kernel2018-01-12
CVE-2017-13214 [HIGH] CWE-20 CVE-2017-13214: In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38495900.
nvd
CVE-2017-0471P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0471 [HIGH] CWE-119 CVE-2017-0471: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0469P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0469 [HIGH] CWE-119 CVE-2017-0469: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0466P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0466 [HIGH] CWE-119 CVE-2017-0466: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0468P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0468 [HIGH] CWE-119 CVE-2017-0468: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd