Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-29 CVE-2017-3750 Unspecified vulnerability in Google Android
On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.
high complexity
google
6.4
2017-06-29 CVE-2017-3749 Unspecified vulnerability in Google Android
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.
high complexity
google
6.4
2017-06-27 CVE-2015-3840 Improper Access Control vulnerability in Google Android
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
local
low complexity
google CWE-284
5.5
2017-06-14 CVE-2017-0647 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-06-14 CVE-2017-0646 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-06-14 CVE-2017-0645 Information Exposure vulnerability in Google Android
An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-06-14 CVE-2017-0644 Unspecified vulnerability in Google Android
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google
5.5
2017-06-14 CVE-2017-0643 Unspecified vulnerability in Google Android
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google
5.5
2017-06-14 CVE-2017-0642 Unspecified vulnerability in Google Android
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google
5.5
2017-06-14 CVE-2017-0641 Improper Initialization vulnerability in Google Android
A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google CWE-665
5.5