Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-16 CVE-2015-8996 Race Condition vulnerability in Google Android
In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.
network
high complexity
google CWE-362
7.6
2017-05-16 CVE-2014-9936 Race Condition vulnerability in Google Android
In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.
network
high complexity
google CWE-362
7.6
2017-05-12 CVE-2017-0635 NULL Pointer Dereference vulnerability in Google Android
A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google CWE-476
7.1
2017-05-12 CVE-2017-0620 Improper Input Validation vulnerability in multiple products
An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
linux google CWE-20
7.6
2017-05-12 CVE-2017-0619 Privilege Escalation vulnerability in Google Android Qualcomm Pin Controller Driver
An elevation of privilege vulnerability in the Qualcomm pin controller driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
linux google
7.6
2017-05-12 CVE-2017-0618 Privilege Escalation vulnerability in Google Android Mediatek Command Queue Driver
An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6
2017-05-12 CVE-2017-0617 Privilege Escalation vulnerability in Google Android Mediatek Video Driver
An elevation of privilege vulnerability in the MediaTek video driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6
2017-05-12 CVE-2017-0616 Privilege Escalation vulnerability in Google Android Mediatek Driver
An elevation of privilege vulnerability in the MediaTek system management interrupt driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6
2017-05-12 CVE-2017-0615 Privilege Escalation vulnerability in Google Android Mediatek Power Driver
An elevation of privilege vulnerability in the MediaTek power driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google
7.6
2017-05-12 CVE-2017-0600 Denial Of Service vulnerability in Google Android Mediaserver
A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot.
network
google
7.1