Vulnerabilities > Google > Android > 3.2.2

DATE CVE VULNERABILITY TITLE RISK
2017-08-09 CVE-2017-0746 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Qualcomm ipa driver.
network
google
6.8
2017-08-09 CVE-2017-0742 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the MediaTek video driver.
network
google
6.8
2017-08-09 CVE-2017-0741 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the MediaTek gpu driver.
network
google
6.8
2017-08-09 CVE-2017-0740 Unspecified vulnerability in Google Android
A remote code execution vulnerability in the Broadcom networking driver.
network
google
6.8
2017-08-07 CVE-2015-3839 NULL Pointer Dereference vulnerability in Google Android
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
local
low complexity
google CWE-476
2.1
2017-07-13 CVE-2017-6249 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6
2017-06-29 CVE-2017-3750 Unspecified vulnerability in Google Android
On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.
local
google lenovo
6.9
2017-06-29 CVE-2017-3749 Unspecified vulnerability in Google Android
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.
local
google lenovo
6.9
2017-06-29 CVE-2017-3748 Local Privilege Escalation vulnerability in Lenovo VIBE Mobile
On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).
local
low complexity
google lenovo
7.2
2017-06-27 CVE-2015-3840 Improper Access Control vulnerability in Google Android
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
local
low complexity
google CWE-284
2.1