← Back

Android

android

Vendor: Google • 8,153 CVEs

CVEs (8,153)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Nvidia
2Android
Shield Tv Firmware
Nov 21, 2024
Mar 6, 2018
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or informa...Show more
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is rated as high.Show less
2Google
Nvidia
2Android
Shield Tv Firmware
Nov 21, 2024
Mar 6, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that i...Show more
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as moderate.Show less
2Google
Nvidia
2Android
Shield Tv Firmware
Nov 21, 2024
Mar 6, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.
2Google
Nvidia
2Android
Shield Tv Firmware
Nov 21, 2024
Mar 6, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as hi...Show more
NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.Show less
1Google
1Android
Nov 21, 2024
Mar 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NVIDIA driver contains a possible out-of-bounds read vulnerability due to a leak which may lead to information disclosure. This issue is rated as moderate. Android: A-63851980.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then subsequently access the already freed buffer.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffer...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integer overflow leading to buffer overflow.Show less
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulner...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulnerability in a buffer size calculation may potentially lead to a buffer overflow.Show less
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, in wma_unified_link_radio_stats_event_handler(), the number of radio channels coming from firmware is not properly validated, potentially le...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, in wma_unified_link_radio_stats_event_handler(), the number of radio channels coming from firmware is not properly validated, potentially leading to an integer overflow vulnerability followed by a buffer overflow.Show less
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management frame, a stack buffer overflow may potentially occur.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a GPU Driver which can potentially lead to a Use After Free condition.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially occur.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authen...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.Show less
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur in WLANFTM_McProcessMsg.Show less
3Debian
GoogleXmlsoft
3Android
Debian LinuxLibxml2
Nov 21, 2024
Feb 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
3Debian
GoogleXmlsoft
3Android
Debian LinuxLibxml2
Dec 3, 2025
Feb 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Dependin...Show more
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).Show less
1Google
1Android
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...Show more
In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-65853158.Show less
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not neede...Show more
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-71486645.Show less
1Google
1Android
Nov 21, 2024
Feb 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.