Github Exploits

401 exploits tracked across all sources.

Sort: Activity Stars
CVE-2016-3865 GITHUB HIGH c
Synaptics touchscreen driver <2016-09-05 - Privilege Escalation
The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.
by codecat007
8 stars
CVSS 7.8
CVE-2016-10296 GITHUB MEDIUM c
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Qualcomm shared memory driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33845464. References: QC-CR#1109782.
by codecat007
8 stars
CVSS 4.7
CVE-2016-10295 GITHUB MEDIUM c
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Qualcomm LED driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33781694. References: QC-CR#1109326.
by codecat007
8 stars
CVSS 4.7
CVE-2016-10294 GITHUB MEDIUM c
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33621829. References: QC-CR#1105481.
by codecat007
8 stars
CVSS 4.7
CVE-2016-10290 GITHUB HIGH c
Linux Kernel - Access Control
An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33898330. References: QC-CR#1109782.
by codecat007
8 stars
CVSS 7.0
CVE-2016-10288 GITHUB HIGH c
Linux Kernel - Access Control
An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33863909. References: QC-CR#1109763.
by codecat007
8 stars
CVSS 7.0
CVE-2016-10285 GITHUB HIGH c
Linux Kernel - Access Control
An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33752702. References: QC-CR#1104899.
by codecat007
8 stars
CVSS 7.0
CVE-2016-0844 GITHUB HIGH c
Qualcomm RF driver <2016-04-01 - Privilege Escalation
The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privileges via a crafted application, aka internal bug 26324307.
by codecat007
8 stars
CVSS 8.4
CVE-2016-0805 GITHUB HIGH c
Android <4.4.4, <5.1.1 LMY49G, <2016-02-01 - Privilege Escalation
The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204.
by codecat007
8 stars
CVSS 8.4
CVE-2020-0022 GITHUB HIGH c
Android -8.0,8.1,9,10 - RCE
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715
by codecat007
8 stars
CVSS 8.8
CVE-2020-0001 GITHUB HIGH c
Android <10 - Privilege Escalation
In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-140055304
by codecat007
8 stars
CVSS 7.8
CVE-2019-9358 GITHUB HIGH c
Android <10 - Privilege Escalation
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120156401
by codecat007
8 stars
CVSS 7.3
CVE-2019-2099 GITHUB HIGH c
Android - Privilege Escalation
In nfa_rw_store_ndef_rx_buf of nfa_rw_act.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-123583388.
by codecat007
8 stars
CVSS 7.8
CVE-2019-2034 GITHUB HIGH c
Android - Memory Corruption
In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the NFC process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-122035770.
by codecat007
8 stars
CVSS 7.8
CVE-2019-2027 GITHUB HIGH c
Android -7.x-9.x - RCE
In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-119120561.
by codecat007
8 stars
CVSS 8.8
CVE-2017-0879 GITHUB CRITICAL c
Android <8.0 - Info Disclosure
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65025028.
by codecat007
8 stars
CVSS 9.1
CVE-2017-0858 GITHUB HIGH c
Android <8.0 - Info Disclosure
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.
by codecat007
8 stars
CVSS 7.5
CVE-2017-0850 GITHUB MEDIUM c
Android <7.1.2 - Info Disclosure
An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-64836941.
by codecat007
8 stars
CVSS 5.3
CVE-2017-0823 GITHUB HIGH c
Android <7.1.2 - Info Disclosure
An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37896655.
by codecat007
8 stars
CVSS 7.5
CVE-2017-0820 GITHUB HIGH c
Android <8.0 - Info Disclosure
A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187433.
by codecat007
8 stars
CVSS 7.5
CVE-2017-0814 GITHUB HIGH c
Android <8.0 - Info Disclosure
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800140.
by codecat007
8 stars
CVSS 7.5
CVE-2017-0813 GITHUB HIGH c
Android <7.1.2 - DoS
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36531046.
by codecat007
8 stars
CVSS 7.5
CVE-2017-0778 GITHUB HIGH c
Android <7.1.2 - Info Disclosure
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.
by codecat007
8 stars
CVSS 7.1
CVE-2017-0777 GITHUB MEDIUM c
Android <7.1.2 - Info Disclosure
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.
by codecat007
8 stars
CVSS 5.5
CVE-2017-0776 GITHUB MEDIUM c
Android <8.0 - Info Disclosure
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.
by codecat007
8 stars
CVSS 5.5