Vulnerabilities > Google > Android > 5.0.2

DATE CVE VULNERABILITY TITLE RISK
2020-04-07 CVE-2017-18648 Improper Input Validation vulnerability in Google Android
An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software.
network
low complexity
google CWE-20
critical
9.1
2020-02-21 CVE-2014-7914 Incorrect Authorization vulnerability in Google Android
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.
network
low complexity
google CWE-863
8.1
2020-01-24 CVE-2015-1530 Integer Overflow or Wraparound vulnerability in Google Android
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.
local
low complexity
google CWE-190
7.8
2020-01-24 CVE-2015-1525 Improper Input Validation vulnerability in Google Android
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
local
low complexity
google CWE-20
5.5
2020-01-08 CVE-2014-9908 Unspecified vulnerability in Google Android 4.4/5.0.2/5.1.1
A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).
low complexity
google
6.5
2018-11-30 CVE-2018-15835 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Android 1.0 through 9.0 has Insecure Permissions.
network
low complexity
google CWE-732
7.5
2018-07-06 CVE-2018-5907 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8
2018-07-06 CVE-2018-11304 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8
2018-05-10 CVE-2018-6254 Out-of-bounds Read vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure.
local
low complexity
google CWE-125
3.3
2018-05-10 CVE-2018-6246 Information Exposure vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure.
network
low complexity
google CWE-200
5.3