Google

Android

8041 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 62.17%
  • Veröffentlicht 09.06.2011 10:36:27
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.

Warnung Medienbericht Exploit
  • EPSS 38.34%
  • Veröffentlicht 09.06.2011 10:36:27
  • Zuletzt bearbeitet 21.04.2026 20:29:52

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-on...

Exploit
  • EPSS 48.78%
  • Veröffentlicht 16.05.2011 17:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 21.04.2011 10:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Androi...

  • EPSS 0.88%
  • Veröffentlicht 31.01.2011 20:00:51
  • Zuletzt bearbeitet 29.04.2026 01:13:23

data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances v...

  • EPSS 78.65%
  • Veröffentlicht 10.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (applic...

  • EPSS 0.98%
  • Veröffentlicht 14.10.2009 10:30:02
  • Zuletzt bearbeitet 23.04.2026 00:35:47

An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656.

  • EPSS 0.83%
  • Veröffentlicht 14.10.2009 10:30:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsE...

Exploit
  • EPSS 1.19%
  • Veröffentlicht 03.08.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at B...

  • EPSS 0.05%
  • Veröffentlicht 17.07.2009 16:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an app...