VYPR

Android SDK

by Google

CVEs (1,089)

  • CVE-2015-6633Dec 8, 2015
    risk 0.00cvss —epss 0.02

    The display drivers in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23987307.

  • CVE-2015-3842Oct 1, 2015
    risk 0.00cvss —epss 0.01

    Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.

  • CVE-2015-3837Oct 1, 2015
    risk 0.00cvss —epss 0.01

    The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an application that sends a…

  • CVE-2015-3833Oct 1, 2015
    risk 0.00cvss —epss 0.01

    The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted…

  • CVE-2013-2300Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The FlickWnn (aka OpenWnn/Flick support) application 2.02 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local filesystem.

  • CVE-2011-1001Jul 8, 2011
    risk 0.00cvss —epss 0.01

    dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more…

  • CVE-2009-0608Feb 17, 2009
    risk 0.00cvss —epss 0.00

    Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines.

  • CVE-2009-0607Feb 17, 2009
    risk 0.00cvss —epss 0.00

    Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.

  • CVE-2009-0606Feb 17, 2009
    risk 0.00cvss —epss 0.00

    The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by…

Page 55 of 55