This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Google First view 2009-10-14
Product Android Last view 2020-06-05
Version * Type Os
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:o:google:android

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
5.5 2020-06-05 CVE-2020-13843

An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).

9.3 2020-03-24 CVE-2019-20606

An issue was discovered on Samsung mobile devices with any (before May 2019) software. A phishing attack against OMACP can change the network and internet settings. The Samsung ID is SVE-2019-14073 (May 2019).

8.1 2020-02-21 CVE-2014-7914

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

2.4 2020-02-12 CVE-2011-2343

The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.

8.8 2020-02-07 CVE-2014-7224

A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.

7.8 2020-01-24 CVE-2015-1530

media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.

5.5 2020-01-24 CVE-2015-1525

audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.

9.8 2020-01-23 CVE-2013-6792

Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability

5.5 2020-01-08 CVE-2016-5346

An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).

5.5 2020-01-07 CVE-2019-9465

In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003

7.8 2020-01-06 CVE-2019-9468

In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471

6.5 2019-07-22 CVE-2019-13098

The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.

7.5 2018-11-30 CVE-2018-15835

Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.

7.8 2018-07-06 CVE-2018-5907

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

7.8 2018-07-06 CVE-2018-11304

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

3.3 2018-05-10 CVE-2018-6254

In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference: N-CVE-2018-6254.

5.3 2018-05-10 CVE-2018-6246

In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure. This issue is rated as moderate. Android: A-69383916. Reference: N-CVE-2018-6246.

7.8 2018-05-02 CVE-2013-6272

The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.

8.8 2018-04-20 CVE-2014-0900

The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.

5.5 2017-12-27 CVE-2015-7889

The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensitive information via a crafted application that sends a crafted intent.

7.8 2017-11-16 CVE-2017-0865

An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-65025090. References: M-ALPS02973195.

7.8 2017-11-16 CVE-2017-0864

An elevation of privilege vulnerability in the MediaTek ioctl (flashlight). Product: Android. Versions: Android kernel. Android ID: A-37277147. References: M-ALPS03394571.

7.8 2017-11-16 CVE-2017-0863

An elevation of privilege vulnerability in the Upstream kernel video driver. Product: Android. Versions: Android kernel. Android ID: A-37950620.

7.8 2017-11-16 CVE-2017-0862

An elevation of privilege vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-36006779.

7.8 2017-11-16 CVE-2017-0843

An elevation of privilege vulnerability in the MediaTek ccci. Product: Android. Versions: Android kernel. Android ID: A-62670819. References: M-ALPS03361488.

CWE : Common Weakness Enumeration

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
%idName
27% (208) CWE-264 Permissions, Privileges, and Access Controls
20% (154) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
15% (115) CWE-200 Information Exposure
7% (55) CWE-20 Improper Input Validation
4% (37) CWE-284 Access Control (Authorization) Issues
4% (32) CWE-189 Numeric Errors
3% (26) CWE-362 Race Condition
2% (22) CWE-190 Integer Overflow or Wraparound
2% (17) CWE-476 NULL Pointer Dereference
2% (16) CWE-416 Use After Free
1% (10) CWE-125 Out-of-bounds Read
1% (9) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...
1% (8) CWE-399 Resource Management Errors
0% (5) CWE-787 Out-of-bounds Write
0% (5) CWE-254 Security Features
0% (4) CWE-310 Cryptographic Issues
0% (4) CWE-19 Data Handling
0% (3) CWE-415 Double Free
0% (3) CWE-275 Permission Issues
0% (2) CWE-326 Inadequate Encryption Strength
0% (2) CWE-191 Integer Underflow (Wrap or Wraparound)
0% (2) CWE-172 Encoding Error
0% (2) CWE-129 Improper Validation of Array Index
0% (2) CWE-1 Location
0% (1) CWE-772 Missing Release of Resource after Effective Lifetime

SAINT Exploits

Description Link
Adobe Flash Player Object Confusion Code Execution More info here
Adobe Flash Player SWF Content Regular Expression Heap Overflow More info here

Open Source Vulnerability Database (OSVDB)

id Description
76552 Google Chrome Multiple Unspecified Same Origin Policy Bypass
74800 Android System Property Space ASHMEM_SET_PROT_MASK Application Sandbox Local ...
74453 Android Browser HTTPS Session HTTP Set-Cookie Header HSTS includeSubDomains W...
73388 Multiple Vendor libc Implentation fnmatch.c Memory Consumption DoS
73383 Apache HTTP Server Portable Runtime (APR) Library apr_fnmatch() Infinite Loop...
72766 Google Android JavaScript Unprompted Arbitrary SD File Access
70744 Google Android Mms Application data/WorkingMessage.java Draft Cache SMS Messa...
67962 Apple Safari WebKit Floating Point Data Crafted HTML Document Handling Arbitr...
58955 Google Android Dalvik API Unspecified Function Remote DoS

ExploitDB Exploits

id Description
35382 Android WAPPushManager - SQL Injection
32959 Adobe Flash Player Regular Expression Heap Overflow
28957 Android Zygote Socket Vulnerability Fork bomb Attack
19369 Adobe Flash Player Object Type Confusion
18164 Android 'content://' URI Multiple Information Disclosure Vulnerabilities
15548 Android 2.0/2.1 Use-After-Free Remote Code Execution on Webkit
15423 Android 2.0-2.1 Reverse Shell Exploit

OpenVAS Exploits

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - November12 (Mac OS X)
File : nvt/gb_adobe_air_mult_vuln_nov12_macosx.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - December12 (Windows)
File : nvt/gb_adobe_air_mult_vuln_dec12_win.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - December12 (Mac OS X)
File : nvt/gb_adobe_air_mult_vuln_dec12_macosx.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - November12 (Windows)
File : nvt/gb_adobe_air_mult_vuln_nov12_win.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - October 12 (Mac OS X)
File : nvt/gb_adobe_air_mult_vuln_oct12_macosx.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - October 12 (Windows)
File : nvt/gb_adobe_air_mult_vuln_oct12_win.nasl
2012-12-14 Name : Adobe Flash Player Multiple Vulnerabilities - December12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln_dec12_win.nasl
2012-12-14 Name : Adobe Flash Player Multiple Vulnerabilities - December12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_dec12_lin.nasl
2012-12-14 Name : Adobe Flash Player Multiple Vulnerabilities - December12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln_dec12_macosx.nasl
2012-12-13 Name : SuSE Update for update openSUSE-SU-2012:0594-1 (update)
File : nvt/gb_suse_2012_0594_1.nasl
2012-12-13 Name : SuSE Update for flash-player openSUSE-SU-2012:1480-1 (flash-player)
File : nvt/gb_suse_2012_1480_1.nasl
2012-11-26 Name : FreeBSD Ports: linux-f10-flashplugin
File : nvt/freebsd_linux-f10-flashplugin5.nasl
2012-11-26 Name : FreeBSD Ports: linux-f10-flashplugin
File : nvt/freebsd_linux-f10-flashplugin4.nasl
2012-11-08 Name : Adobe Flash Player Multiple Vulnerabilities - November12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln_nov12_win.nasl
2012-11-08 Name : Adobe Flash Player Multiple Vulnerabilities - November12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln_nov12_macosx.nasl
2012-11-08 Name : Adobe Flash Player Multiple Vulnerabilities - November12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_nov12_lin.nasl
2012-10-15 Name : Adobe Flash Player Multiple Vulnerabilities - Oct12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_oct12_lin.nasl
2012-10-15 Name : Adobe Flash Player Multiple Vulnerabilities - October 12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln_oct12_macosx.nasl
2012-10-15 Name : Adobe Flash Player Multiple Vulnerabilities - October 12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln_oct12_win.nasl
2012-09-15 Name : Gentoo Security Advisory GLSA 201209-01 (adobe-flash)
File : nvt/glsa_201209_01.nasl
2012-09-10 Name : Slackware Advisory SSA:2011-133-01 apr/apr-util
File : nvt/esoft_slk_ssa_2011_133_01.nasl
2012-09-03 Name : Adobe Flash Player Multiple Vulnerabilities - Sep12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_sep12_lin.nasl
2012-08-30 Name : FreeBSD Ports: firefox
File : nvt/freebsd_firefox69.nasl
2012-08-24 Name : Adobe Flash Player Multiple Vulnerabilities -01 August 12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln01_aug12_macosx.nasl
2012-08-24 Name : Adobe Flash Player Multiple Vulnerabilities -01 August 12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln01_aug12_win.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2015-A-0221 Multiple Vulnerabilities in Adobe Flash Player and AIR
Severity: Category I - VMSKEY: V0061469
2013-A-0168 Multiple Vulnerabilities In Adobe Flash Player
Severity: Category I - VMSKEY: V0040297

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date Description
2019-12-24 Google Android libstagefright integer underflow attempt
RuleID : 52289 - Type : OS-MOBILE - Revision : 1
2019-12-24 Google Android libstagefright integer underflow attempt
RuleID : 52288 - Type : OS-MOBILE - Revision : 1
2019-12-10 Android Stagefright MP4 buffer overflow attempt
RuleID : 52101 - Type : OS-MOBILE - Revision : 1
2019-12-10 Android Stagefright MP4 buffer overflow attempt
RuleID : 52100 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51866 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51865 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51864 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51863 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51862 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51861 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51860 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51859 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51858 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51857 - Type : OS-MOBILE - Revision : 1
2019-09-19 Adobe Flash player memory corruption attempt
RuleID : 51082 - Type : FILE-FLASH - Revision : 1
2019-09-19 Adobe Flash player memory corruption attempt
RuleID : 51081 - Type : FILE-FLASH - Revision : 1
2018-03-27 Adobe Flash Player ByteArray shading memory leak attempt
RuleID : 45744 - Type : FILE-FLASH - Revision : 1
2018-03-27 Adobe Flash Player ByteArray shading memory leak attempt
RuleID : 45743 - Type : FILE-FLASH - Revision : 1
2018-05-23 Linux Kernel Challenge ACK provocation attempt
RuleID : 40063-community - Type : OS-LINUX - Revision : 5
2016-10-11 Linux Kernel Challenge ACK provocation attempt
RuleID : 40063 - Type : OS-LINUX - Revision : 5
2016-03-14 Adobe Flash Player malformed mp4 CABAC encoding out of bounds read attempt
RuleID : 36513 - Type : FILE-MULTIMEDIA - Revision : 2
2016-03-14 Adobe Flash Player malformed mp4 CABAC encoding out of bounds read attempt
RuleID : 36512 - Type : FILE-MULTIMEDIA - Revision : 2
2016-03-14 Adobe Flash Player invalid vector length memory corruption attempt
RuleID : 36374 - Type : FILE-FLASH - Revision : 2
2016-03-14 Adobe Flash Player invalid vector length memory corruption attempt
RuleID : 36373 - Type : FILE-FLASH - Revision : 2
2016-03-14 Adobe Flash Player invalid vector length memory corruption attempt
RuleID : 36372 - Type : FILE-FLASH - Revision : 2

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2018-04-27 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2018-1062.nasl - Type: ACT_GATHER_INFO
2018-02-28 Name: The version of Arista Networks EOS running on the remote device is affected b...
File: arista_eos_sa0023.nasl - Type: ACT_GATHER_INFO
2017-12-14 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3659.nasl - Type: ACT_GATHER_INFO
2017-12-14 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2017-0174.nasl - Type: ACT_GATHER_INFO
2017-12-11 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3657.nasl - Type: ACT_GATHER_INFO
2017-12-11 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3658.nasl - Type: ACT_GATHER_INFO
2017-12-11 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2017-0173.nasl - Type: ACT_GATHER_INFO
2017-11-08 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2017-0168.nasl - Type: ACT_GATHER_INFO
2017-11-03 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3636.nasl - Type: ACT_GATHER_INFO
2017-11-03 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3637.nasl - Type: ACT_GATHER_INFO
2017-11-03 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2017-2920-1.nasl - Type: ACT_GATHER_INFO
2017-09-20 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2017-2525-1.nasl - Type: ACT_GATHER_INFO
2017-09-19 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-3422-1.nasl - Type: ACT_GATHER_INFO
2017-09-11 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2017-2389-1.nasl - Type: ACT_GATHER_INFO
2017-08-25 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2017-1842.nasl - Type: ACT_GATHER_INFO
2017-08-25 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3609.nasl - Type: ACT_GATHER_INFO
2017-08-25 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2017-0145.nasl - Type: ACT_GATHER_INFO
2017-08-22 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20170801_kernel_on_SL7_x.nasl - Type: ACT_GATHER_INFO
2017-08-21 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3606.nasl - Type: ACT_GATHER_INFO
2017-08-21 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3607.nasl - Type: ACT_GATHER_INFO
2017-08-21 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2017-0144.nasl - Type: ACT_GATHER_INFO
2017-08-18 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3945.nasl - Type: ACT_GATHER_INFO
2017-08-18 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3605.nasl - Type: ACT_GATHER_INFO
2017-08-18 Name: The remote OracleVM host is missing one or more security updates.
File: oraclevm_OVMSA-2017-0143.nasl - Type: ACT_GATHER_INFO
2017-08-16 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-1842-1.nasl - Type: ACT_GATHER_INFO