Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 101 of 339
CVE-2017-13180P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-01-12
CVE-2017-13180 [HIGH] CWE-416 CVE-2017-13180: In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use af
In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution priv
nvd
CVE-2020-0408P3HIGHCVSS 7.8v8.0v8.1+4 more2020-10-14
CVE-2020-0408 [HIGH] CWE-190 CVE-2020-0408: In remove of String16.cpp, there is a possible out of bounds write due to an integer overflow. This
In remove of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-156999009
nvd
CVE-2020-0036P3HIGHCVSS 7.8v8.0v8.1+3 more2020-03-10
CVE-2020-0036 [HIGH] CWE-863 CVE-2020-0036: In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions du
In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A
nvd
CVE-2019-2128P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2128 [HIGH] CWE-787 CVE-2019-2128: In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check
In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Andr
nvd
CVE-2019-2178P3HIGHCVSS 7.8v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2178 [HIGH] CWE-787 CVE-2019-2178: In rw_t4t_sm_read_ndef of rw_t4t in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of
In rw_t4t_sm_read_ndef of rw_t4t in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9492P3HIGHCVSS 7.8v8.0v8.1+1 more2018-10-02
CVE-2018-9492 [HIGH] CWE-863 CVE-2018-9492: In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions byp
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-111934948
nvd
CVE-2018-9585P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-02-11
CVE-2018-9585 [HIGH] CWE-787 CVE-2018-9585: In nfc_ncif_proc_get_routing of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.
In nfc_ncif_proc_get_routing of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android
nvd
CVE-2018-9584P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-02-11
CVE-2018-9584 [HIGH] CWE-787 CVE-2018-9584: In nfc_ncif_set_config_status of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8
In nfc_ncif_set_config_status of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android
nvd
CVE-2019-2192P3HIGHCVSS 7.8v9.0v10.0+1 more2019-11-13
CVE-2019-2192 [HIGH] CWE-20 CVE-2019-2192: In call of SliceProvider.java, there is a possible permissions bypass due to improper input validati
In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-138441555
nvd
CVE-2019-2011P3HIGHCVSS 7.8v8.0v8.1+2 more2019-06-19
CVE-2019-2011 [HIGH] CWE-787 CVE-2019-2011: In readNullableNativeHandleNoDup of Parcel.cpp, there is a possible out of bounds write due to a mis
In readNullableNativeHandleNoDup of Parcel.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-120084106
nvd
CVE-2019-1993P3HIGHCVSS 7.8v8.0v8.1+1 more2019-02-28
CVE-2019-1993 [HIGH] CWE-190 CVE-2019-1993: In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. Thi
In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-119819889.
nvd
CVE-2018-9525P3HIGHCVSS 7.8v9.02018-11-14
CVE-2018-9525 [HIGH] CVE-2018-9525: In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings
In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings.slice.action.WIFI_CHANGED, there is a possible permissions bypass due to a confused deputy. This could lead to local escalation of privilege, allowing a local attacker to change device settings, with no additional execution privileges needed. User interaction is
nvd
CVE-2018-9522P3HIGHCVSS 7.8v9.02018-11-14
CVE-2018-9522 [HIGH] CWE-787 CVE-2018-9522: In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write
In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write due to unnecessary functionality which may be abused. This could lead to local escalation of privilege in the system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Andr
nvd
CVE-2019-2203P3HIGHCVSS 7.8v8.0v8.1+3 more2019-11-13
CVE-2019-2203 [HIGH] CWE-787 CVE-2019-2203: In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-137370777
nvd
CVE-2019-2210P3HIGHCVSS 7.8v9.0v10.0+1 more2019-11-13
CVE-2019-2210 [HIGH] CWE-787 CVE-2019-2210: In load_logging_config of qmi_vs_service.cc, there is a possible out of bounds write due to a heap b
In load_logging_config of qmi_vs_service.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-139148442
nvd
CVE-2019-2202P3HIGHCVSS 7.8v9.0v10.0+1 more2019-11-13
CVE-2019-2202 [HIGH] CWE-787 CVE-2019-2202: In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-137283376
nvd
CVE-2019-2120P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2120 [HIGH] CWE-1188 CVE-2019-2120: In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption i
In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 A
nvd
CVE-2020-0081P3HIGHCVSS 7.8v8.0v8.1+3 more2020-04-17
CVE-2020-0081 [HIGH] CWE-415 CVE-2020-0081: In finalize of AssetManager.java, there is possible memory corruption due to a double free. This cou
In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144028297
nvd
CVE-2020-0306P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0306 [HIGH] CVE-2020-0306: In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservatio
In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480
nvd
CVE-2020-0026P3HIGHCVSS 7.8v8.0v8.1+3 more2020-02-13
CVE-2020-0026 [HIGH] CWE-416 CVE-2020-0026: In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free.
In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140419401
nvd