Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 100 of 339
CVE-2019-2115P3HIGHCVSS 7.8v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2115 [HIGH] CWE-415 CVE-2019-2115: In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is pos
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0227P3HIGHCVSS 7.8v8.0v8.1+6 more2020-07-17
CVE-2020-0227 [HIGH] CWE-862 CVE-2020-0227: In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers
nvd
CVE-2020-0421P3HIGHCVSS 7.8v8.0v8.1+4 more2020-10-14
CVE-2020-0421 [HIGH] CWE-755 CVE-2020-0421: In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error hand
In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-161894517
nvd
CVE-2020-0418P3HIGHCVSS 7.8v10.0vAndroid-102020-11-10
CVE-2020-0418 [HIGH] CVE-2020-0418: In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escala
In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153879813
nvd
CVE-2020-0442P3HIGHCVSS 7.5v8.0v8.1+4 more2020-11-10
CVE-2020-0442 [HIGH] CWE-20 CVE-2020-0442: In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improp
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Androi
nvd
CVE-2020-0241P3HIGHCVSS 7.8v8.0v8.1+3 more2020-08-11
CVE-2020-0241 [HIGH] CWE-415 CVE-2020-0241: In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to
In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151456667
nvd
CVE-2020-0155P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0155 [HIGH] CWE-787 CVE-2020-0155: In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due t
In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736386
nvd
CVE-2020-0209P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0209 [HIGH] CWE-276 CVE-2020-0209: In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lea
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206842
nvd
CVE-2021-0392P3HIGHCVSS 7.8v8.1v9.0+3 more2021-03-10
CVE-2021-0392 [HIGH] CWE-415 CVE-2021-0392: In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to
In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-175124730
nvd
CVE-2021-0437P3HIGHCVSS 7.8v8.1v9.0+3 more2021-04-13
CVE-2021-0437 [HIGH] CWE-415 CVE-2021-0437: In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalat
In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-176168330
nvd
CVE-2020-0137P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0137 [HIGH] CWE-862 CVE-2020-0137: In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking per
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141920289
nvd
CVE-2017-13184P3HIGHCVSS 7.8v8.0v8.12018-01-12
CVE-2017-13184 [HIGH] CWE-416 CVE-2017-13184: In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyn
In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android I
nvd
CVE-2021-0511P3HIGHCVSS 7.8v9.0v10.0+2 more2021-06-21
CVE-2021-0511 [HIGH] CWE-20 CVE-2021-0511: In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper inp
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-178055795
nvd
CVE-2017-13210P3HIGHCVSS 7.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13210 [HIGH] CWE-787 CVE-2017-13210: In CameraDeviceClient::submitRequestList of CameraDeviceClient.cpp, there is an out-of-bounds write
In CameraDeviceClient::submitRequestList of CameraDeviceClient.cpp, there is an out-of-bounds write if metadataSize is too small. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5
nvd
CVE-2018-9582P3HIGHCVSS 7.8v8.0v8.1+1 more2019-02-11
CVE-2018-9582 [HIGH] CWE-610 CVE-2018-9582: In package installer in Android-8.0, Android-8.1 and Android-9, there is a possible bypass of the un
In package installer in Android-8.0, Android-8.1 and Android-9, there is a possible bypass of the unknown source warning due to a confused deputy scenario. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-112031362.
nvd
CVE-2021-0970P3HIGHCVSS 7.8v9.0v10.0+3 more2021-12-15
CVE-2021-0970 [HIGH] CWE-502 CVE-2021-0970: In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deseriali
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196970023
nvd
CVE-2019-2017P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-19
CVE-2019-2017 [HIGH] CWE-787 CVE-2019-2017: In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out-of-bound write due to a m
In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
CVE-2019-1985P3HIGHCVSS 7.8v7.0v7.1.1+3 more2019-06-19
CVE-2019-1985 [HIGH] CVE-2019-1985: In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass
In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A
nvd
CVE-2017-13288P3HIGHCVSS 7.8v8.0v8.12018-04-04
CVE-2017-13288 [HIGH] CWE-682 CVE-2017-13288: In writeToParcel and readFromParcel of PeriodicAdvertisingReport.java, there is a permission bypass
In writeToParcel and readFromParcel of PeriodicAdvertisingReport.java, there is a permission bypass due to a 64/32bit int mismatch. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Andr
nvd
CVE-2019-2195P3HIGHCVSS 7.8v8.0v8.1+3 more2019-11-13
CVE-2019-2195 [HIGH] CWE-20 CVE-2019-2195: In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-1
nvd