Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-08 CVE-2017-0756 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libstagefright).
local
low complexity
google CWE-367
7.8
2017-09-08 CVE-2017-0755 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Android libraries (libminikin).
local
low complexity
google
7.8
2017-09-08 CVE-2017-0753 Unspecified vulnerability in Google Android
A remote code execution vulnerability in the Android libraries (libgdx).
local
low complexity
google
7.8
2017-09-08 CVE-2017-0752 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
A elevation of privilege vulnerability in the Android framework (windowmanager).
local
low complexity
google CWE-732
7.8
2017-08-24 CVE-2017-0805 Improper Validation of Array Index vulnerability in Google Android
A elevation of privilege vulnerability in the Android media framework (libstagefright).
local
low complexity
google CWE-129
7.8
2017-08-18 CVE-2017-9685 Use After Free vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After Free condition.
network
high complexity
google CWE-416
8.1
2017-08-18 CVE-2017-9684 Use After Free vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.
local
high complexity
google CWE-416
7.0
2017-08-18 CVE-2017-9680 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may use an uninitialized structure to log an error message.
network
low complexity
google CWE-200
7.5
2017-08-18 CVE-2017-9679 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents can leak to system logs.
network
low complexity
google CWE-200
7.5
2017-08-18 CVE-2017-9678 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a video driver, memory corruption can potentially occur due to lack of bounds checking in a memcpy().
local
low complexity
google CWE-119
7.8