Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-06 CVE-2017-0674 Improper Input Validation vulnerability in Google Android
A remote code execution vulnerability in the Android media framework.
local
low complexity
google CWE-20
7.8
2017-07-06 CVE-2017-0673 Unspecified vulnerability in Google Android
A remote code execution vulnerability in the Android media framework.
local
low complexity
google
7.8
2017-07-06 CVE-2017-0671 Unspecified vulnerability in Google Android 4.4.4
A remote code execution vulnerability in the Android libraries.
local
low complexity
google
7.8
2017-07-06 CVE-2017-0667 Improper Input Validation vulnerability in Google Android
A elevation of privilege vulnerability in the Android framework.
local
low complexity
google CWE-20
7.8
2017-07-06 CVE-2017-0666 Incorrect Calculation vulnerability in Google Android
A elevation of privilege vulnerability in the Android framework.
local
low complexity
google CWE-682
7.8
2017-07-06 CVE-2017-0665 Improper Input Validation vulnerability in Google Android
A elevation of privilege vulnerability in the Android framework.
local
low complexity
google CWE-20
7.8
2017-07-06 CVE-2017-0664 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Android framework.
local
low complexity
google
7.8
2017-06-29 CVE-2017-3748 Unspecified vulnerability in Google Android
On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).
local
low complexity
google
7.8
2017-06-14 CVE-2017-0663 Out-of-bounds Write vulnerability in Google Android
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process.
local
low complexity
google CWE-787
7.8
2017-06-14 CVE-2017-0649 Unspecified vulnerability in Google Android 7.1.2
An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
google
7.0