Vulnerabilities > Google > Android > 2.2.3

DATE CVE VULNERABILITY TITLE RISK
2014-12-15 CVE-2014-8507 SQL Injection vulnerability in Google Android
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135.
network
low complexity
google CWE-89
7.5
2014-09-04 CVE-2014-6060 Resource Management Errors vulnerability in multiple products
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
low complexity
dhcpcd-project google CWE-399
3.3
2014-04-29 CVE-2013-7373 Information Exposure vulnerability in Google Android
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
network
low complexity
google CWE-200
7.5
2014-04-29 CVE-2013-7372 Cryptographic Issues vulnerability in multiple products
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Architecture (JCA) in Android before 4.4 and other products, when no seed is provided by the user, uses an incorrect offset value, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging the resulting PRNG predictability, as exploited in the wild against Bitcoin wallet applications in August 2013.
network
low complexity
apache google CWE-310
5.0
2014-03-31 CVE-2013-6775 Permissions, Privileges, and Access Controls vulnerability in Chainfire Supersu 1.69
The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.
network
low complexity
chainfire google CWE-264
critical
10.0
2014-03-31 CVE-2013-6774 Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier, and Chainfire SuperSU package before 1.69 for Android 4.2.x and earlier allows attackers to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process.
network
low complexity
chainfire google androidsu koushik-dutta
critical
10.0
2014-03-31 CVE-2013-6768 Path Traversal vulnerability in Koushik Dutta Superuser 1.0.2.1
Untrusted search path vulnerability in the CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier allows attackers to trigger the launch of a Trojan horse app_process program via a crafted PATH environment variable for a /system/xbin/su process.
network
low complexity
koushik-dutta google CWE-22
5.0
2014-03-03 CVE-2014-1939 Code Injection vulnerability in multiple products
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
network
low complexity
google lenovo CWE-94
7.5
2013-07-10 CVE-2013-3347 Numeric Errors vulnerability in Adobe Flash Player
Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.
network
low complexity
adobe microsoft apple linux google CWE-189
critical
10.0
2013-07-10 CVE-2013-3345 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Flash Player
Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
network
low complexity
adobe microsoft apple linux google CWE-119
critical
10.0