Google

Android

8032 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.59%
  • Veröffentlicht 30.11.2012 12:54:16
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service via an application that uses cr...

  • EPSS 0.22%
  • Veröffentlicht 30.11.2012 12:54:16
  • Zuletzt bearbeitet 11.04.2025 00:51:21

drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2 allows attackers to cause a denial of service (NULL pointer dereference) via an application that uses crafted arguments in a ...

  • EPSS 10.07%
  • Veröffentlicht 07.10.2012 15:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application.

  • EPSS 1.48%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.

  • EPSS 18.38%
  • Veröffentlicht 27.01.2012 15:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wro...

  • EPSS 0.16%
  • Veröffentlicht 25.01.2012 18:55:12
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.

  • EPSS 0.5%
  • Veröffentlicht 25.10.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selec...

  • EPSS 0.36%
  • Veröffentlicht 03.10.2011 15:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain...

  • EPSS 5.27%
  • Veröffentlicht 12.08.2011 18:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tab...

  • EPSS 0.23%
  • Veröffentlicht 09.08.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to ...