Vulnerabilities > Google > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-08-05 CVE-2014-9902 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android internal bug 28668638 and Qualcomm internal bugs CR553937 and CR553941.
network
low complexity
google CWE-119
critical
10.0
2016-07-23 CVE-2016-1706 Improper Input Validation vulnerability in Google Chrome
The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.
network
low complexity
google CWE-20
critical
9.6
2016-07-11 CVE-2016-3811 Permissions, Privileges, and Access Controls vulnerability in Google Android
The kernel video driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28447556.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3808 Permissions, Privileges, and Access Controls vulnerability in Google Android
The serial peripheral interface driver in Android before 2016-07-05 on Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28430009.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3807 Permissions, Privileges, and Access Controls vulnerability in Google Android
The serial peripheral interface driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28402196.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3806 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28402341 and MediaTek internal bug ALPS02715341.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3805 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek power management driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28333002 and MediaTek internal bug ALPS02694412.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3804 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek power management driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28332766 and MediaTek internal bug ALPS02694410.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3803 Permissions, Privileges, and Access Controls vulnerability in Google Android
The kernel filesystem implementation in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28588434.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3802 Permissions, Privileges, and Access Controls vulnerability in Google Android
The kernel filesystem implementation in Android before 2016-07-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28271368.
network
google CWE-264
critical
9.3