Google Inc Android vulnerabilities
959 known vulnerabilities affecting google_inc/android.
Total CVEs
959
CISA KEV
0
Public exploits
21
Exploited in wild
1
Severity breakdown
CRITICAL70HIGH617MEDIUM268LOW4
Vulnerabilities
Page 9 of 48
CVE-2017-0473P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0473 [HIGH] CWE-119 CVE-2017-0473: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0472P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0472 [HIGH] CWE-119 CVE-2017-0472: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0470P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0470 [HIGH] CWE-119 CVE-2017-0470: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0467P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-03-08
CVE-2017-0467 [HIGH] CWE-119 CVE-2017-0467: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0408P3HIGHCVSS 7.8vAndroid-7.1.12017-02-08
CVE-2017-0408 [HIGH] CVE-2017-0408: A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted f
A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-32769670.
nvd
CVE-2017-0409P3HIGHCVSS 7.8vAndroid-6.0vAndroid-6.0.1+2 more2017-02-08
CVE-2017-0409 [HIGH] CVE-2017-0409: A remote code execution vulnerability in libstagefright could enable an attacker using a specially c
A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID:
nvd
CVE-2018-9531P3HIGHCVSS 7.8vAndroid-92018-11-14
CVE-2018-9531 [HIGH] CWE-787 CVE-2018-9531: In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a miss
In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112661641
nvd
CVE-2017-13248P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13248 [HIGH] CWE-787 CVE-2017-13248: In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due t
In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due to a missing bounds check. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-7034961
nvd
CVE-2017-13249P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13249 [HIGH] CWE-787 CVE-2017-13249: In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a miss
In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70399408.
nvd
CVE-2018-9577P3HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9577 [HIGH] CWE-787 CVE-2018-9577: In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of
In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715937.
nvd
CVE-2018-9575P3HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9575 [HIGH] CWE-787 CVE-2018-9575: In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds wri
In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619387.
nvd
CVE-2018-9574P3HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9574 [HIGH] CWE-787 CVE-2018-9574: In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bound
In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619337.
nvd
CVE-2018-9573P3HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9573 [HIGH] CWE-787 CVE-2018-9573: In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due t
In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116467350.
nvd
CVE-2018-9576P3HIGHCVSS 7.8vAndroid-92018-12-07
CVE-2018-9576 [HIGH] CWE-787 CVE-2018-9576: In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bo
In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715245.
nvd
CVE-2018-9362P3HIGHCVSS 7.5vAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.12018-11-06
CVE-2018-9362 [HIGH] CWE-20 CVE-2018-9362: In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to
In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-
nvd
CVE-2018-9568P3HIGHCVSS 7.8vAndroid kernel2018-12-06
CVE-2018-9568 [HIGH] CWE-704 CVE-2018-9568: In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.
nvd
CVE-2018-9565P3HIGHCVSS 7.5vAndroid-166805582018-12-06
CVE-2018-9565 [HIGH] CWE-125 CVE-2018-9565: In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. Th
In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.
nvd
CVE-2018-9422P3HIGHCVSS 7.8vAndroid kernel2018-11-06
CVE-2018-9422 [HIGH] CWE-416 CVE-2018-9422: In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to l
In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-74250718 References: Upstream kernel.
nvd
CVE-2017-13182P3HIGHCVSS 7.8v8.0v8.12018-01-12
CVE-2017-13182 [HIGH] CWE-190 CVE-2017-13182: In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to
In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0,
nvd
CVE-2017-13289P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13289 [HIGH] CWE-131 CVE-2017-13289: In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a writ
In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch. This could lead to a local escalation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions
nvd