Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-30 CVE-2017-10709 Improper Authentication vulnerability in Google Android 6.0
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.
local
low complexity
google elephone CWE-287
7.2
2017-06-29 CVE-2017-3748 Local Privilege Escalation vulnerability in Lenovo VIBE Mobile
On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).
local
low complexity
google lenovo
7.2
2017-06-14 CVE-2017-0663 Out-of-bounds Write vulnerability in Google Android
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process.
local
low complexity
google CWE-787
7.8
2017-06-14 CVE-2017-0649 Privilege Escalation vulnerability in Google Android 7.1.2
An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6
2017-06-14 CVE-2017-0644 Memory Corruption vulnerability in Google Android Media Framework
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google
7.1
2017-06-14 CVE-2017-0643 Memory Corruption vulnerability in Google Android Media Framework
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google
7.1
2017-06-14 CVE-2017-0642 Memory Corruption vulnerability in Google Android Media Framework
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google
7.1
2017-06-14 CVE-2017-0641 Improper Initialization vulnerability in Google Android
A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google CWE-665
7.1
2017-06-14 CVE-2017-0640 Memory Corruption vulnerability in Google Android Media Framework
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google
7.1
2017-06-14 CVE-2017-0636 Privilege Escalation vulnerability in Google Android 7.1.2
An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6