Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2018-01-18 CVE-2017-17860 Improper Input Validation vulnerability in Google Android
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key.
low complexity
google CWE-20
5.7
2018-01-16 CVE-2017-11072 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while calculating CRC for GPT header fields with partition entries greater than 16384 buffer overflow occurs.
local
low complexity
google CWE-119
7.8
2018-01-12 CVE-2017-13226 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek mtk.
local
low complexity
google
7.8
2018-01-12 CVE-2017-13225 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In libMtkOmxVdec.so there is a possible heap buffer overflow.
local
low complexity
google CWE-119
7.8
2018-01-12 CVE-2017-13222 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Upstream kernel kernel.
network
low complexity
google CWE-200
7.5
2018-01-12 CVE-2017-13221 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the Upstream kernel wifi driver.
local
low complexity
google
7.8
2018-01-12 CVE-2017-13220 Type Confusion vulnerability in Google Android
An elevation of privilege vulnerability in the Upstream kernel bluez.
local
low complexity
google CWE-843
7.8
2018-01-12 CVE-2017-13219 Unspecified vulnerability in Google Android
A denial of service vulnerability in the Upstream kernel synaptics touchscreen controller.
network
low complexity
google
7.5
2018-01-12 CVE-2017-13218 Information Exposure vulnerability in Google Android
Access to CNTVCT_EL0 in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear could be used for side channel attacks and this could lead to local information disclosure with no additional execution privileges needed in FSM9055, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, QCA4531, QCA9980, QCN5502, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845.
local
high complexity
google CWE-200
4.7
2018-01-12 CVE-2017-13217 Out-of-bounds Write vulnerability in Google Android
In DisplayFtmItem in the bootloader, there is an out-of-bounds write due to reading a string without verifying that it's null-terminated.
local
low complexity
google CWE-787
7.8