Google Vulnerabilities and Affected Products
Vulnerabilities associated with android_kernel.
Products
Clear product- Chrome4,306 vulnerabilities
- Android1,376 vulnerabilities
- pixel56 vulnerabilities
- Chromium V839 vulnerabilities
- ChromeOS12 vulnerabilities
- android_kernel6 vulnerabilities
- AngularJS6 vulnerabilities
- Chromium6 vulnerabilities
- gRPC6 vulnerabilities
- MCP Toolbox for Databases (googleapis/mcp-toolbox)6 vulnerabilities
- mcp-toolbox5 vulnerabilities
- gVisor4 vulnerabilities
- Keras4 vulnerabilities
- Nearby3 vulnerabilities
- admob2 vulnerabilities
- Andrioid2 vulnerabilities
- Chromium Blink2 vulnerabilities
- Chromium Intents2 vulnerabilities
- Chromium Mojo2 vulnerabilities
- Chromium Skia2 vulnerabilities
- Fuchsia2 vulnerabilities
- libjxl2 vulnerabilities
- MCP Toolbox for Databases2 vulnerabilities
- Nest Wifi Pro2 vulnerabilities
- Omaha2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-32917HIGH | In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CWE-787Jun 13, 2024 | CVSS7.1v3.1 | EPSS0.078% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32911CRITICAL | There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS9.8v3.1 | EPSS0.192% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32906HIGH | In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS7.8v3.1 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32899HIGH | In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS7.0v3.1 | EPSS0.078% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29752HIGH | In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CWE-787Apr 5, 2024 | CVSS7.8v3.1 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35656HIGH | In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. CWE-125Oct 18, 2023 | CVSS7.5v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |