Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 109 of 339
CVE-2019-9397P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9397 [HIGH] CWE-20 CVE-2019-9397: In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lea
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115747410
nvd
CVE-2019-9401P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9401 [HIGH] CWE-20 CVE-2019-9401: In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lea
In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115375248
nvd
CVE-2019-9389P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9389 [HIGH] CWE-125 CVE-2019-9389: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117567058
nvd
CVE-2019-9390P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9390 [HIGH] CWE-125 CVE-2019-9390: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117551475
nvd
CVE-2019-9329P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9329 [HIGH] CWE-908 CVE-2019-9329: In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to r
In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112917952
nvd
CVE-2017-11060P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11060 [HIGH] CWE-125 CVE-2017-11060: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_PASSPOINT_LIST and QCA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_LIST cfg80211 vendor commands in __wlan_hdd_cfg80211_set_passpoint_list and hdd_extscan
nvd
CVE-2017-11064P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11064 [HIGH] CWE-125 CVE-2017-11064: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_PASSPOINT_LIST and QCA_NL80211_VENDOR_SUBCMD_EXTSCAN_PNO_SET_LIST cfg80211 vendor commands in __wlan_hdd_cfg80211_set_passpoint_list and hdd_extscan
nvd
CVE-2015-6642P3CRITICALCVSS 9.8v5.1.0v6.0+1 more2016-01-06
CVE-2015-6642 [CRITICAL] CWE-264 CVE-2015-6642: The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensi
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.
nvd
CVE-2022-20234P3HIGHCVSS 7.5v12.1vAndroid-12L2022-07-13
CVE-2022-20234 [HIGH] CWE-732 CVE-2022-20234: In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessCo
In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a benign pkgTitle (e.g. Settings app) to make users enable notification access permission for the malicious app. That i
nvd
CVE-2025-3012P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-3012 [HIGH] CVE-2025-3012: In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to r
In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2017-0828P3CRITICALCVSS 9.8≤ 8.02017-10-04
CVE-2017-0828 [CRITICAL] CVE-2017-0828: An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Androi
An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.
nvd
CVE-2017-0824P3CRITICALCVSS 9.8≤ 8.02017-10-04
CVE-2017-0824 [CRITICAL] CVE-2017-0824: An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: And
An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.
nvd
CVE-2019-20560P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20560 [CRITICAL] CWE-787 CVE-2019-20560: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The BIOSUB Trustlet has an out of bounds write. The Samsung ID is SVE-2019-15261 (October 2019).
nvd
CVE-2019-20563P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20563 [CRITICAL] CWE-787 CVE-2019-20563: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The SEC_FR trustlet has an out of bounds write. The Samsung ID is SVE-2019-15272 (October 2019).
nvd
CVE-2019-20544P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20544 [CRITICAL] CWE-787 CVE-2019-20544: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos chipsets) software.
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos chipsets) software. There is an out-of-bounds write in the ICCC Trustlet. The Samsung ID is SVE-2019-15274 (November 2019).
nvd
CVE-2019-20562P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20562 [CRITICAL] CWE-120 CVE-2019-20562: An issue was discovered on Samsung mobile devices with P(9.0) (with TEEGRIS) software. There is a bu
An issue was discovered on Samsung mobile devices with P(9.0) (with TEEGRIS) software. There is a buffer overflow in the BIOSUB Trustlet. The Samsung ID is SVE-2019-15264 (October 2019).
nvd
CVE-2019-20556P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20556 [CRITICAL] CWE-787 CVE-2019-20556: An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos
An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos7885, exynos9610, and exynos9820 chipsets) software. RKP memory corruption allows attackers to control the effective address in EL2. The Samsung ID is SVE-2019-15221 (October 2019).
nvd
CVE-2019-20782P3CRITICALCVSS 9.8v7.0v7.1+3 more2020-04-17
CVE-2019-20782 [CRITICAL] CWE-120 CVE-2019-20782: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. L
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. LG Advanced Flash (LAF) has a buffer overflow. The LG ID is LVE-SMP-190001 (March 2019).
nvd
CVE-2017-18661P3CRITICALCVSS 9.8v6.0v7.0+3 more2020-04-07
CVE-2017-18661 [CRITICAL] CWE-120 CVE-2017-18661: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer overflow in process_cipher_tdea. The Samsung ID is SVE-2017-8973 (July 2017).
nvd
CVE-2017-18660P3CRITICALCVSS 9.8v6.0v7.0+3 more2020-04-07
CVE-2017-18660 [CRITICAL] CWE-120 CVE-2017-18660: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer overflow in tlc_server. The Samsung ID is SVE-2017-8888 (July 2017).
nvd