Google

Android

8032 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.88%
  • Veröffentlicht 08.07.2011 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the t...

  • EPSS 62.17%
  • Veröffentlicht 09.06.2011 10:36:27
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.

Warnung Medienbericht Exploit
  • EPSS 34.39%
  • Veröffentlicht 09.06.2011 10:36:27
  • Zuletzt bearbeitet 22.10.2025 01:15:40

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-on...

Exploit
  • EPSS 54.11%
  • Veröffentlicht 16.05.2011 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.04.2011 10:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Androi...

  • EPSS 0.88%
  • Veröffentlicht 31.01.2011 20:00:51
  • Zuletzt bearbeitet 11.04.2025 00:51:21

data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances v...

  • EPSS 78.65%
  • Veröffentlicht 10.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (applic...

  • EPSS 0.98%
  • Veröffentlicht 14.10.2009 10:30:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656.

  • EPSS 0.83%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsE...

Exploit
  • EPSS 1.19%
  • Veröffentlicht 03.08.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at B...