Nexus 5
Vendor:
First CVE: May 9, 2016 · Active for 10 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nexus 5 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2016
10 years ago
Most Recent CVE
Dec 8, 2023
960 days ago
CVE Severity & Scoring
Nexus 59 CVEs
44%
56%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (77.8%)
Network1 (11.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0997HIGH WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola | Sep 26, 2017 | 7.5 | 30 | NO | YES |
CVE-2016-2431HIGH The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted applica | May 9, 2016 | 7.8 | 28 | NO | NO |
CVE-2023-45866MEDIUM Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentiall | Dec 8, 2023 | 6.3 | 26 | NO | NO |
CVE-2016-2443HIGH The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525. | May 9, 2016 | 7.0 | 24 | NO | NO |
CVE-2016-2432HIGH The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 259 | May 9, 2016 | 7.8 | 24 | NO | NO |
CVE-2014-9888HIGH arch/arm/mm/dma-mapping.c in the Linux kernel before 3.13 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not prevent executable DMA ma | Aug 6, 2016 | 7.8 | 20 | NO | NO |
CVE-2016-2454MEDIUM The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug | May 9, 2016 | 5.5 | 20 | NO | NO |
CVE-2016-2459MEDIUM mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to ob | May 9, 2016 | 5.5 | 17 | NO | NO |
CVE-2016-6684MEDIUM The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Android One devices allows attackers to obtain sensitive information via | Oct 10, 2016 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Nexus 5
Top CWEs
Versions
No cataloged versions.