VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2015-8998
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2014-9932
In TrustZone, an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel due to an improper address range computation.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2014-9964
In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2016-6737
An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30928456.
Published 2016-11-25 · Modified
9.3EPSS 0.006
CVE-2014-9962
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2014-9965
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2015-9026
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2015-9027
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2016-5864
In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In another function, a missing check for a lower bound may result in an out of bounds memory access.
Published 2017-08-16 · Modified
9.3EPSS 0.006
CVE-2016-6729
An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30977990. References: Qualcomm QC-CR#977684.
Published 2016-11-25 · Modified
9.3EPSS 0.006
CVE-2014-9803
arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28557020.
Published 2016-07-11 · Modified
9.3EPSS 0.006
CVE-2018-6271
NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software delivers extra data with the buffer and does not properly validated the extra data, which may lead to denial of service or escalation of privileges. Android ID: A-80198474.
Published 2019-02-13 · Modified
9.3EPSS 0.006
CVE-2016-3873
The NVIDIA kernel in Android before 2016-09-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 29518457.
Published 2016-09-11 · Modified
9.3EPSS 0.006
CVE-2015-9020
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2015-9033
In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2014-9967
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2016-10231
An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.
Published 2018-04-04 · Modified
9.3EPSS 0.006
CVE-2016-10238
In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2016-3868
The Qualcomm power driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28967028 and Qualcomm internal bug CR1032875.
Published 2016-09-11 · Modified
9.3EPSS 0.006
CVE-2016-3869
The Broadcom Wi-Fi driver in Android before 2016-09-05 on Nexus 5, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29009982 and Broadcom internal bug RB#96070.
Published 2016-09-11 · Modified
9.3EPSS 0.006
CVE-2016-2469
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27531992.
Published 2016-06-13 · Modified
9.3EPSS 0.006
CVE-2015-9000
In TrustZone an untrusted pointer dereference vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2015-9002
In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2015-9003
In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2014-9933
Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not have access.
Published 2017-05-16 · Modified
9.3EPSS 0.006
CVE-2016-10338
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2016-10341
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2015-7717
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.
Published 2015-10-06 · Modified
9.3EPSS 0.006
CVE-2015-3865
The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.
Published 2015-10-06 · Modified
9.3EPSS 0.006
CVE-2015-3879
Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.
Published 2015-10-06 · Modified
9.3EPSS 0.006
CVE-2015-6596
mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a different vulnerability than CVE-2015-7717.
Published 2015-10-06 · Modified
9.3EPSS 0.006
CVE-2017-11069
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.
Published 2018-01-10 · Modified
9.3EPSS 0.006
CVE-2017-15849
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a LayerStack can be destroyed in between Validate and Commit by the application resulting in a Use After Free condition.
Published 2018-01-10 · Modified
9.3EPSS 0.006
CVE-2014-9781
Buffer overflow in drivers/video/fbcmap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28410333 and Qualcomm internal bug CR556471.
Published 2016-07-11 · Modified
9.3EPSS 0.006
CVE-2014-9784
Multiple buffer overflows in drivers/char/diag/diag_debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28442449 and Qualcomm internal bug CR585147.
Published 2016-07-11 · Modified
9.3EPSS 0.006
CVE-2014-9786
Heap-based buffer overflow in drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28557260 and Qualcomm internal bug CR545979.
Published 2016-07-11 · Modified
9.3EPSS 0.006
CVE-2015-9029
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.
Published 2017-06-13 · Modified
9.3EPSS 0.006
CVE-2016-3934
drivers/media/platform/msm/camera_v2/sensor/io/msm_camera_cci_i2c.c in the Qualcomm camera driver in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices relies on variable-length arrays, which allows attackers to gain privileges via a crafted application, aka Android internal bug 30102557 and Qualcomm internal bug CR 789704.
Published 2016-10-10 · Modified
9.3EPSS 0.006
CVE-2017-11043
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a WiFI driver function, an integer overflow leading to heap buffer overflow may potentially occur.
Published 2017-12-05 · Modified
9.3EPSS 0.006
CVE-2016-8423
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-31399736. References: QC-CR#1000546.
Published 2017-01-12 · Modified
9.3EPSS 0.006
← Prev24 / 93Next →