VYPR

Android

by Google

CVEs (8,504)

  • CVE-2014-7953HigJul 7, 2017
    risk 0.46cvss 7.0epss 0.00

    Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script…

  • CVE-2017-6248HigJul 6, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product:…

  • CVE-2017-0649HigJun 14, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and because of…

  • CVE-2017-0636HigJun 14, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product:…

  • CVE-2017-7372HigJun 13, 2017
    risk 0.46cvss 7.0epss 0.00

    In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.

  • CVE-2017-7370HigJun 13, 2017
    risk 0.46cvss 7.0epss 0.00

    In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.

  • CVE-2017-7368HigJun 13, 2017
    risk 0.46cvss 7.0epss 0.00

    In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.

  • CVE-2016-10339HigJun 13, 2017
    risk 0.46cvss 7.1epss 0.01

    In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.

  • CVE-2015-9022HigJun 13, 2017
    risk 0.46cvss 7.0epss 0.00

    In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.

  • CVE-2014-9966HigJun 13, 2017
    risk 0.46cvss 7.0epss 0.00

    In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.

  • CVE-2016-10297HigJun 6, 2017
    risk 0.46cvss 7.0epss 0.00

    In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

  • CVE-2014-9941HigJun 6, 2017
    risk 0.46cvss 7.0epss 0.00

    In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

  • CVE-2016-10242HigMay 16, 2017
    risk 0.46cvss 7.0epss 0.00

    A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.

  • CVE-2015-8997HigMay 16, 2017
    risk 0.46cvss 7.0epss 0.00

    In TrustZone a time-of-check time-of-use race condition could potentially exist in a listener routine in all Android releases from CAF using the Linux kernel.

  • CVE-2015-8996HigMay 16, 2017
    risk 0.46cvss 7.0epss 0.00

    In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.

  • CVE-2014-9936HigMay 16, 2017
    risk 0.46cvss 7.0epss 0.01

    In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.

  • CVE-2017-8244HigMay 12, 2017
    risk 0.46cvss 7.0epss 0.00

    In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by different threads at the same time, but they are not protected with mutex or locks. Buffer overflow…

  • CVE-2017-0623HigMay 12, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the HTC bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…

  • CVE-2017-0622HigMay 12, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product:…

  • CVE-2017-0621HigMay 12, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…

Page 212 of 426