Vulnerabilities > Google > Android > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2016-10390 Resource Management Errors vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.
network
low complexity
google CWE-399
critical
9.8
2017-08-18 CVE-2016-10391 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2016-10392 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.
network
low complexity
google CWE-119
critical
9.8
2017-08-18 CVE-2016-5871 Integer Overflow or Wraparound vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an image file.
network
low complexity
google CWE-190
critical
9.8
2017-08-18 CVE-2016-5872 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are not properly validated.
network
low complexity
google CWE-20
critical
9.8
2017-04-17 CVE-2016-6726 Unspecified vulnerability in Google Android
Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.
network
low complexity
google
critical
9.8
2017-04-17 CVE-2016-6727 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.
network
low complexity
google CWE-264
critical
9.8
2017-04-13 CVE-2016-1155 Injection vulnerability in Google Android
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
network
low complexity
google CWE-74
critical
9.8
2017-04-13 CVE-2014-7920 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges.
network
low complexity
google CWE-264
critical
9.8
2017-04-13 CVE-2014-7921 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges.
network
low complexity
google CWE-264
critical
9.8