Vulnerabilities > Google > Android > 4.0.1

DATE CVE VULNERABILITY TITLE RISK
2020-06-05 CVE-2020-13843 Improper Input Validation vulnerability in Google Android
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01.
local
low complexity
google CWE-20
4.9
2020-02-21 CVE-2014-7914 Incorrect Authorization vulnerability in Google Android
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.
network
google CWE-863
5.8
2020-02-07 CVE-2014-7224 Improper Input Validation vulnerability in Google Android
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.
network
low complexity
google CWE-20
critical
9.0
2020-01-24 CVE-2015-1530 Integer Overflow or Wraparound vulnerability in Google Android
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.
local
low complexity
google CWE-190
7.8
2020-01-24 CVE-2015-1525 Improper Input Validation vulnerability in Google Android
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
local
low complexity
google CWE-20
5.5
2020-01-23 CVE-2013-6792 Unspecified vulnerability in Google Android
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
network
low complexity
google
7.5
2020-01-08 CVE-2016-5346 Information Exposure vulnerability in Google Android
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).
local
low complexity
google CWE-200
2.1
2020-01-07 CVE-2019-9465 Unspecified vulnerability in Google Android
In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause.
local
low complexity
google
2.1
2018-11-30 CVE-2018-15835 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Android 1.0 through 9.0 has Insecure Permissions.
network
low complexity
google CWE-732
5.0
2018-07-06 CVE-2018-5907 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8