Vulnerabilities > Google > Android > 6.0.1

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2017-13299 Unspecified vulnerability in Google Android
A other vulnerability in the Android media framework (libavc).
network
low complexity
google
7.5
2018-04-04 CVE-2017-13298 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android media framework (libhavc).
network
low complexity
google CWE-200
5.3
2018-04-04 CVE-2017-13297 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android media framework (libhevc).
network
low complexity
google CWE-200
5.3
2018-04-04 CVE-2017-13296 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android media framework (libavc).
network
low complexity
google CWE-200
5.3
2018-04-04 CVE-2017-13295 Improper Input Validation vulnerability in Google Android
A denial of service vulnerability in the Android framework (package installer).
network
low complexity
google CWE-20
5.3
2018-04-04 CVE-2017-13294 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android framework (aosp email application).
network
low complexity
google CWE-200
5.3
2018-04-04 CVE-2017-13290 Out-of-bounds Read vulnerability in Google Android
In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
6.2
2018-04-04 CVE-2017-13289 Incorrect Calculation of Buffer Size vulnerability in Google Android
In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch.
local
low complexity
google CWE-131
7.8
2018-04-04 CVE-2017-13285 Out-of-bounds Write vulnerability in Google Android
In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer.
network
low complexity
google CWE-787
critical
9.8
2018-04-04 CVE-2017-13284 Improper Input Validation vulnerability in Google Android
In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation.
network
low complexity
google CWE-20
critical
9.8