Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-14 CVE-2017-0640 Unspecified vulnerability in Google Android
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google
5.5
2017-06-14 CVE-2017-0639 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-06-13 CVE-2017-8242 Race Condition vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.
network
high complexity
google CWE-362
5.9
2017-06-13 CVE-2017-8239 Information Exposure vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are not sanitized potentially leading to exposure of kernel memory.
local
low complexity
google CWE-200
5.5
2017-06-13 CVE-2017-8235 Unspecified vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a memory structure in a camera driver is not properly protected.
local
low complexity
google
5.5
2017-06-13 CVE-2017-7366 Improper Input Validation vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.
local
low complexity
google CWE-20
5.5
2017-06-13 CVE-2016-10337 Improper Input Validation vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
local
low complexity
google CWE-20
5.5
2017-06-13 CVE-2016-10336 7PK - Security Features vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
local
low complexity
google CWE-254
5.5
2017-06-13 CVE-2016-10335 Improper Access Control vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
local
low complexity
google CWE-284
5.5
2017-06-13 CVE-2016-10334 Improper Access Control vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
local
low complexity
google CWE-284
5.5