VYPR

Vendor CVEs

Google

All CVEs

16,116 total · sorted by risk
  • CVE-2016-10332MedJun 13, 2017
    risk 0.36cvss 5.5epss 0.01

    In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.

  • CVE-2015-9024MedJun 13, 2017
    risk 0.36cvss 5.5epss 0.01

    In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.

  • CVE-2015-9021MedJun 13, 2017
    risk 0.36cvss 5.5epss 0.01

    In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.

  • CVE-2014-9951MedJun 6, 2017
    risk 0.36cvss 5.5epss 0.00

    In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.

  • CVE-2014-9947MedJun 6, 2017
    risk 0.36cvss 5.5epss 0.00

    In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

  • CVE-2015-9001MedMay 16, 2017
    risk 0.36cvss 5.5epss 0.01

    In TrustZone an information exposure vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.

  • CVE-2017-0635MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android.…

  • CVE-2017-0626MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user…

  • CVE-2017-0625MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user…

  • CVE-2017-0624MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission.…

  • CVE-2017-0602MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product:…

  • CVE-2017-0601MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product:…

  • CVE-2017-0600MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android.…

  • CVE-2017-0599MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.01

    A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,…

  • CVE-2017-0598MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that…

  • CVE-2017-0493MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions:…

  • CVE-2016-10292MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: Kernel-3.10,…

  • CVE-2017-0560MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing device protection. Product: Android. Versions: 4.4.4, 5.0.2,…

  • CVE-2017-0559MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in libskia could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2,…

  • CVE-2017-0558MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4,…

  • CVE-2017-0557MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions:…

  • CVE-2017-0556MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions:…

  • CVE-2017-0555MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions:…

  • CVE-2017-0552MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,…

  • CVE-2017-0551MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,…

  • CVE-2017-0550MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,…

  • CVE-2017-0549MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0,…

  • CVE-2017-0548MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 7.0, 7.1.1. Android…

  • CVE-2017-0547MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application…

  • CVE-2016-5349MedApr 6, 2017
    risk 0.36cvss 5.5epss 0.01

    The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client.…

  • CVE-2017-0529MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product:…

  • CVE-2017-0499MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to the possibility of a temporary denial of service. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android…

  • CVE-2017-0498MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability in Setup Wizard could allow a local attacker to require Google account sign-in after a factory reset. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.1.1, 6.0, 6.0.1,…

  • CVE-2017-0496MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability in Setup Wizard could allow a local malicious application to temporarily block access to an affected device. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.0.2, 5.1.1,…

  • CVE-2017-0495MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions:…

  • CVE-2017-0494MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product:…

  • CVE-2017-0492MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either…

  • CVE-2017-0491MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    An elevation of privilege vulnerability in Package Manager could enable a local malicious application to prevent users from uninstalling applications or removing permissions from applications. This issue is rated as Moderate because it is a local bypass of user interaction…

  • CVE-2017-0490MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to delete user data. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission.…

  • CVE-2017-0489MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.00

    An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions:…

  • CVE-2017-0488MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0,…

  • CVE-2017-0487MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0,…

  • CVE-2017-0486MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0,…

  • CVE-2017-0485MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0,…

  • CVE-2017-0484MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0,…

  • CVE-2017-0483MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0,…

  • CVE-2017-0482MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0,…

  • CVE-2017-0336MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product:…

  • CVE-2017-0334MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product:…

  • CVE-2016-8483MedMar 8, 2017
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission.…

Page 231 of 323