This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Google First view 2009-10-14
Product Android Last view 2021-07-14
Version - Type Os
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:o:google:android

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
5.5 2021-07-14 CVE-2021-0654

In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168802517References: N/A

8.8 2021-07-14 CVE-2021-0592

In various functions in WideVine, there are possible out of bounds writes due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-188061006

7.8 2021-07-14 CVE-2021-0577

In flv extractor, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-187161771

3.3 2021-07-08 CVE-2021-25439

Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.

7.8 2021-07-08 CVE-2021-25438

Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.

3.3 2021-07-08 CVE-2021-25432

Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.

7.8 2021-06-22 CVE-2021-0608

In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174870704

7.8 2021-06-22 CVE-2021-0607

In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-180950209

6.7 2021-06-22 CVE-2021-0606

In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168034487

7 2021-06-21 CVE-2021-0533

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193932

7 2021-06-21 CVE-2021-0532

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185196177

7.8 2021-06-21 CVE-2021-0531

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185195272

7.8 2021-06-21 CVE-2021-0530

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185196175

7.8 2021-06-21 CVE-2021-0529

In memory management driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185195268

7.8 2021-06-21 CVE-2021-0528

In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185195266

7.8 2021-06-21 CVE-2021-0527

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193931

7.8 2021-06-21 CVE-2021-0526

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185195264

7.8 2021-06-21 CVE-2021-0525

In memory management driver, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193929

7.8 2021-06-21 CVE-2021-0512

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

6.8 2021-06-14 CVE-2021-0467

In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-174490700

9.8 2021-06-14 CVE-2021-0324

Product: AndroidVersions: Android SoCAndroid ID: A-175402462

3.3 2021-06-11 CVE-2021-25403

Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.

7.8 2021-06-11 CVE-2021-0498

In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-183461321

7.8 2021-06-11 CVE-2021-0497

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-183461320

7.8 2021-06-11 CVE-2021-0496

In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-183467912

CWE : Common Weakness Enumeration

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
%idName
19% (247) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
17% (221) CWE-264 Permissions, Privileges, and Access Controls
11% (150) CWE-200 Information Exposure
8% (107) CWE-416 Use After Free
7% (99) CWE-787 Out-of-bounds Write
6% (80) CWE-125 Out-of-bounds Read
5% (69) CWE-20 Improper Input Validation
3% (50) CWE-190 Integer Overflow or Wraparound
3% (48) CWE-362 Race Condition
2% (30) CWE-189 Numeric Errors
2% (28) CWE-284 Access Control (Authorization) Issues
1% (20) CWE-415 Double Free
1% (19) CWE-269 Improper Privilege Management
1% (16) CWE-476 NULL Pointer Dereference
1% (16) CWE-129 Improper Validation of Array Index
1% (16) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...
0% (9) CWE-732 Incorrect Permission Assignment for Critical Resource
0% (7) CWE-665 Improper Initialization
0% (6) CWE-399 Resource Management Errors
0% (4) CWE-191 Integer Underflow (Wrap or Wraparound)
0% (4) CWE-19 Data Handling
0% (3) CWE-798 Use of Hard-coded Credentials
0% (3) CWE-772 Missing Release of Resource after Effective Lifetime
0% (3) CWE-310 Cryptographic Issues
0% (3) CWE-276 Incorrect Default Permissions

SAINT Exploits

Description Link
Adobe Flash Player Object Confusion Code Execution More info here
Adobe Flash Player SWF Content Regular Expression Heap Overflow More info here

Open Source Vulnerability Database (OSVDB)

id Description
76552 Google Chrome Multiple Unspecified Same Origin Policy Bypass
74800 Android System Property Space ASHMEM_SET_PROT_MASK Application Sandbox Local ...
72766 Google Android JavaScript Unprompted Arbitrary SD File Access
70744 Google Android Mms Application data/WorkingMessage.java Draft Cache SMS Messa...
67962 Apple Safari WebKit Floating Point Data Crafted HTML Document Handling Arbitr...
58955 Google Android Dalvik API Unspecified Function Remote DoS

ExploitDB Exploits

id Description
35382 Android WAPPushManager - SQL Injection
32959 Adobe Flash Player Regular Expression Heap Overflow
28957 Android Zygote Socket Vulnerability Fork bomb Attack
19369 Adobe Flash Player Object Type Confusion
18164 Android 'content://' URI Multiple Information Disclosure Vulnerabilities
15548 Android 2.0/2.1 Use-After-Free Remote Code Execution on Webkit
15423 Android 2.0-2.1 Reverse Shell Exploit

OpenVAS Exploits

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - December12 (Mac OS X)
File : nvt/gb_adobe_air_mult_vuln_dec12_macosx.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - December12 (Windows)
File : nvt/gb_adobe_air_mult_vuln_dec12_win.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - November12 (Mac OS X)
File : nvt/gb_adobe_air_mult_vuln_nov12_macosx.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - November12 (Windows)
File : nvt/gb_adobe_air_mult_vuln_nov12_win.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - October 12 (Mac OS X)
File : nvt/gb_adobe_air_mult_vuln_oct12_macosx.nasl
2013-03-28 Name : Adobe Air Multiple Vulnerabilities - October 12 (Windows)
File : nvt/gb_adobe_air_mult_vuln_oct12_win.nasl
2012-12-14 Name : Adobe Flash Player Multiple Vulnerabilities - December12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln_dec12_win.nasl
2012-12-14 Name : Adobe Flash Player Multiple Vulnerabilities - December12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_dec12_lin.nasl
2012-12-14 Name : Adobe Flash Player Multiple Vulnerabilities - December12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln_dec12_macosx.nasl
2012-12-13 Name : SuSE Update for flash-player openSUSE-SU-2012:1480-1 (flash-player)
File : nvt/gb_suse_2012_1480_1.nasl
2012-12-13 Name : SuSE Update for flash-player openSUSE-SU-2012:0723-1 (flash-player)
File : nvt/gb_suse_2012_0723_1.nasl
2012-12-13 Name : SuSE Update for update openSUSE-SU-2012:0594-1 (update)
File : nvt/gb_suse_2012_0594_1.nasl
2012-11-26 Name : FreeBSD Ports: linux-f10-flashplugin
File : nvt/freebsd_linux-f10-flashplugin4.nasl
2012-11-26 Name : FreeBSD Ports: linux-f10-flashplugin
File : nvt/freebsd_linux-f10-flashplugin5.nasl
2012-11-08 Name : Adobe Flash Player Multiple Vulnerabilities - November12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln_nov12_macosx.nasl
2012-11-08 Name : Adobe Flash Player Multiple Vulnerabilities - November12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln_nov12_win.nasl
2012-11-08 Name : Adobe Flash Player Multiple Vulnerabilities - November12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_nov12_lin.nasl
2012-10-15 Name : Adobe Flash Player Multiple Vulnerabilities - Oct12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_oct12_lin.nasl
2012-10-15 Name : Adobe Flash Player Multiple Vulnerabilities - October 12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln_oct12_win.nasl
2012-10-15 Name : Adobe Flash Player Multiple Vulnerabilities - October 12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln_oct12_macosx.nasl
2012-09-15 Name : Gentoo Security Advisory GLSA 201209-01 (adobe-flash)
File : nvt/glsa_201209_01.nasl
2012-09-03 Name : Adobe Flash Player Multiple Vulnerabilities - Sep12 (Linux)
File : nvt/gb_adobe_flash_player_mult_vuln_sep12_lin.nasl
2012-08-24 Name : Adobe Flash Player Multiple Vulnerabilities -01 August 12 (Mac OS X)
File : nvt/gb_adobe_prdts_mult_vuln01_aug12_macosx.nasl
2012-08-24 Name : Adobe Flash Player Multiple Vulnerabilities -01 August 12 (Windows)
File : nvt/gb_adobe_prdts_mult_vuln01_aug12_win.nasl
2012-08-10 Name : Gentoo Security Advisory GLSA 201206-21 (Adobe Flash Player)
File : nvt/glsa_201206_21.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2013-A-0168 Multiple Vulnerabilities In Adobe Flash Player
Severity: Category I - VMSKEY: V0040297

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date Description
2020-03-31 Android Binder use after free exploit attempt
RuleID : 53345 - Type : OS-MOBILE - Revision : 1
2020-03-31 Android Binder use after free exploit attempt
RuleID : 53344 - Type : OS-MOBILE - Revision : 1
2019-12-24 Google Android libstagefright integer underflow attempt
RuleID : 52289 - Type : OS-MOBILE - Revision : 1
2019-12-24 Google Android libstagefright integer underflow attempt
RuleID : 52288 - Type : OS-MOBILE - Revision : 1
2019-12-10 Android Stagefright MP4 buffer overflow attempt
RuleID : 52101 - Type : OS-MOBILE - Revision : 1
2019-12-10 Android Stagefright MP4 buffer overflow attempt
RuleID : 52100 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51866 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51865 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51864 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51863 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51862 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51861 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51860 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51859 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51858 - Type : OS-MOBILE - Revision : 1
2019-11-15 Android Stagefright MP4 buffer overflow attempt
RuleID : 51857 - Type : OS-MOBILE - Revision : 1
2018-05-23 Linux Kernel Challenge ACK provocation attempt
RuleID : 40063-community - Type : OS-LINUX - Revision : 5
2016-10-11 Linux Kernel Challenge ACK provocation attempt
RuleID : 40063 - Type : OS-LINUX - Revision : 5
2015-09-03 Android Stagefright MP4 buffer overflow attempt
RuleID : 35435 - Type : OS-MOBILE - Revision : 5
2015-09-03 Android Stagefright MP4 buffer overflow attempt
RuleID : 35434 - Type : OS-MOBILE - Revision : 5
2015-02-11 Android ObjectInputStream privilege escalation attempt
RuleID : 32975 - Type : OS-MOBILE - Revision : 3
2015-02-11 Android ObjectInputStream privilege escalation attempt
RuleID : 32974 - Type : OS-MOBILE - Revision : 3
2014-09-23 Astrum exploit kit Adobe Flash exploit payload request
RuleID : 31968-community - Type : EXPLOIT-KIT - Revision : 1
2014-11-16 Astrum exploit kit Adobe Flash exploit payload request
RuleID : 31968 - Type : EXPLOIT-KIT - Revision : 2
2014-11-16 CottonCastle exploit kit Adobe flash outbound connection
RuleID : 31276 - Type : EXPLOIT-KIT - Revision : 4

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2019-01-11 Name: The remote Virtuozzo host is missing a security update.
File: Virtuozzo_VZA-2018-086.nasl - Type: ACT_GATHER_INFO
2019-01-11 Name: The remote Virtuozzo host is missing a security update.
File: Virtuozzo_VZA-2018-088.nasl - Type: ACT_GATHER_INFO
2019-01-10 Name: The remote device is affected by multiple vulnerabilities.
File: juniper_space_jsa10917_184R1.nasl - Type: ACT_GATHER_INFO
2018-12-28 Name: The remote EulerOS host is missing multiple security updates.
File: EulerOS_SA-2018-1432.nasl - Type: ACT_GATHER_INFO
2018-11-16 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2018-3083.nasl - Type: ACT_GATHER_INFO
2018-10-04 Name: The remote Debian host is missing a security update.
File: debian_DLA-1531.nasl - Type: ACT_GATHER_INFO
2018-10-02 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4308.nasl - Type: ACT_GATHER_INFO
2018-09-18 Name: The remote EulerOS Virtualization host is missing multiple security updates.
File: EulerOS_SA-2018-1234.nasl - Type: ACT_GATHER_INFO
2018-08-31 Name: The remote Virtuozzo host is missing multiple security updates.
File: Virtuozzo_VZA-2018-063.nasl - Type: ACT_GATHER_INFO
2018-08-20 Name: The remote Virtuozzo host is missing multiple security updates.
File: Virtuozzo_VZA-2018-055.nasl - Type: ACT_GATHER_INFO
2018-08-15 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2018-2384.nasl - Type: ACT_GATHER_INFO
2018-08-15 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2018-2390.nasl - Type: ACT_GATHER_INFO
2018-07-16 Name: The remote Debian host is missing a security update.
File: debian_DLA-1422.nasl - Type: ACT_GATHER_INFO
2018-05-30 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2018-1023.nasl - Type: ACT_GATHER_INFO
2018-05-15 Name: The remote Virtuozzo host is missing multiple security updates.
File: Virtuozzo_VZA-2018-029.nasl - Type: ACT_GATHER_INFO
2018-05-10 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2018-1319.nasl - Type: ACT_GATHER_INFO
2018-05-03 Name: The remote Debian host is missing a security update.
File: debian_DLA-1369.nasl - Type: ACT_GATHER_INFO
2018-05-02 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4187.nasl - Type: ACT_GATHER_INFO
2018-04-27 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2018-1062.nasl - Type: ACT_GATHER_INFO
2018-04-20 Name: The remote Amazon Linux 2 host is missing a security update.
File: al2_ALAS-2018-994.nasl - Type: ACT_GATHER_INFO
2018-02-28 Name: The version of Arista Networks EOS running on the remote device is affected b...
File: arista_eos_sa0023.nasl - Type: ACT_GATHER_INFO
2018-02-23 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4120.nasl - Type: ACT_GATHER_INFO
2018-01-29 Name: The remote EulerOS host is missing multiple security updates.
File: EulerOS_SA-2018-1031.nasl - Type: ACT_GATHER_INFO
2017-12-26 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2017-937.nasl - Type: ACT_GATHER_INFO
2017-12-14 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2017-3659.nasl - Type: ACT_GATHER_INFO