Vulnerabilities
Vulnerable Software
Google:  >> Android  >> 4.0  Security Vulnerabilities
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.
CVSS Score
8.8
EPSS Score
0.022
Published
2020-02-07
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-01-24
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-01-24
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
CVSS Score
9.8
EPSS Score
0.028
Published
2020-01-23
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).
CVSS Score
5.5
EPSS Score
0.001
Published
2020-01-08
In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003
CVSS Score
5.5
EPSS Score
0.0
Published
2020-01-07
In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471
CVSS Score
7.8
EPSS Score
0.0
Published
2020-01-06
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.
CVSS Score
6.5
EPSS Score
0.006
Published
2019-07-22
Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
CVSS Score
7.5
EPSS Score
0.061
Published
2018-11-30
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
CVSS Score
7.8
EPSS Score
0.0
Published
2018-07-06


Contact Us

Shodan ® - All rights reserved