Vulnerabilities > Google > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-04-13 CVE-2016-1155 Injection vulnerability in Google Android
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
network
low complexity
google CWE-74
critical
9.8
2017-04-13 CVE-2014-7921 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges.
network
low complexity
google CWE-264
critical
9.8
2017-04-13 CVE-2014-7920 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges.
network
low complexity
google CWE-264
critical
9.8
2017-04-11 CVE-2013-6647 Use After Free vulnerability in Google Chrome
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.
network
low complexity
google CWE-416
critical
9.8
2017-04-04 CVE-2016-10229 Improperly Implemented Security Check for Standard vulnerability in multiple products
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
network
low complexity
linux google CWE-358
critical
9.8
2017-02-08 CVE-2016-8418 Improper Access Control vulnerability in Google Android
A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel.
network
low complexity
google CWE-284
critical
9.8
2017-01-27 CVE-2016-8411 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Buffer overflow vulnerability while processing QMI QOS TLVs.
network
low complexity
google CWE-119
critical
9.8
2016-11-25 CVE-2016-6725 Improper Access Control vulnerability in Google Android
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel.
network
low complexity
google CWE-284
critical
9.8
2016-10-31 CVE-2016-7990 7PK - Errors vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.
network
low complexity
google CWE-388
critical
9.8
2016-10-10 CVE-2016-6696 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm internal bug CR 1041130.
network
low complexity
google CWE-20
critical
9.8