Vulnerabilities > Google > Android > 5.1.1

DATE CVE VULNERABILITY TITLE RISK
2020-04-07 CVE-2017-18648 Improper Input Validation vulnerability in Google Android
An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software.
network
low complexity
google CWE-20
critical
9.1
2020-01-08 CVE-2014-9908 Unspecified vulnerability in Google Android 4.4/5.0.2/5.1.1
A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).
low complexity
google
6.5
2018-11-30 CVE-2018-15835 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Android 1.0 through 9.0 has Insecure Permissions.
network
low complexity
google CWE-732
7.5
2018-07-06 CVE-2018-5907 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8
2018-07-06 CVE-2018-11304 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8
2018-05-10 CVE-2018-6254 Out-of-bounds Read vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure.
local
low complexity
google CWE-125
3.3
2018-05-10 CVE-2018-6246 Information Exposure vulnerability in Google Android
In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure.
network
low complexity
google CWE-200
5.3
2018-04-04 CVE-2017-13269 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android system (bluetooth).
low complexity
google CWE-200
4.3
2018-04-04 CVE-2017-13268 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android system (bluetooth).
low complexity
google CWE-200
4.3
2018-04-04 CVE-2017-13266 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check.
network
low complexity
google CWE-119
critical
9.8