Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-7366 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters. | ||
| CVE-2016-10337 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed. | ||
| CVE-2016-10336 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot. | ||
| CVE-2016-10335 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. | ||
| CVE-2016-10334 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten. | ||
| CVE-2016-10333 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. | ||
| CVE-2016-10332 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications. | ||
| CVE-2015-9024 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications. | ||
| CVE-2015-9021 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled. | ||
| CVE-2014-9951 | Med | 0.36 | 5.5 | 0.01 | Jun 6, 2017 | In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist. | ||
| CVE-2014-9947 | Med | 0.36 | 5.5 | 0.01 | Jun 6, 2017 | In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist. | ||
| CVE-2015-9001 | Med | 0.36 | 5.5 | 0.01 | May 16, 2017 | In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linux kernel. | ||
| CVE-2017-0635 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android.… | ||
| CVE-2017-0626 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user… | ||
| CVE-2017-0625 | Med | 0.36 | 5.5 | 0.00 | May 12, 2017 | An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user… | ||
| CVE-2017-0624 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission.… | ||
| CVE-2017-0602 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product:… | ||
| CVE-2017-0601 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product:… | ||
| CVE-2017-0600 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android.… | ||
| CVE-2017-0599 | Med | 0.36 | 5.5 | 0.01 | May 12, 2017 | A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,… |
- risk 0.36cvss 5.5epss 0.00
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
- risk 0.36cvss 5.5epss 0.01
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.
- risk 0.36cvss 5.5epss 0.01
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.
- risk 0.36cvss 5.5epss 0.01
In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
- risk 0.36cvss 5.5epss 0.01
A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android.…
- risk 0.36cvss 5.5epss 0.01
An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user…
- risk 0.36cvss 5.5epss 0.00
An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user…
- risk 0.36cvss 5.5epss 0.01
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission.…
- risk 0.36cvss 5.5epss 0.01
An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product:…
- risk 0.36cvss 5.5epss 0.01
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product:…
- risk 0.36cvss 5.5epss 0.01
A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android.…
- risk 0.36cvss 5.5epss 0.01
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,…
Page 352 of 426