Google

Android

8032 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 06.07.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37008096.

  • EPSS 0.27%
  • Veröffentlicht 06.07.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37208566.

Medienbericht
  • EPSS 0.03%
  • Veröffentlicht 30.06.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.

  • EPSS 0.02%
  • Veröffentlicht 29.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).

  • EPSS 0.01%
  • Veröffentlicht 29.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.

  • EPSS 0.01%
  • Veröffentlicht 29.06.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-374...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.06.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.

  • EPSS 0.08%
  • Veröffentlicht 14.06.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a p...

  • EPSS 0.78%
  • Veröffentlicht 14.06.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote...

  • EPSS 0.44%
  • Veröffentlicht 14.06.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary...