cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 11 of 339
CVE-2016-6727P3CRITICALCVSS 9.8≤ 7.1.12017-04-17
CVE-2016-6727 [CRITICAL] CWE-264 CVE-2016-6727: The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbi The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.
nvd
CVE-2018-9476P3CRITICALCVSS 9.8v8.0v8.12018-10-02
CVE-2018-9476 [CRITICAL] CWE-416 CVE-2018-9476: In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper loc In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper locking. This could lead to remote escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-10969911
nvd
CVE-2017-13160P3CRITICALCVSS 9.8v7.0v7.1.1+2 more2017-12-06
CVE-2017-13160 [CRITICAL] CWE-125 CVE-2017-13160: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-37160362.
nvd
CVE-2019-2045P3CRITICALCVSS 9.8v7.0v7.1.1+4 more2019-05-08
CVE-2019-2045 [CRITICAL] CWE-787 CVE-2019-2045: In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This c In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Andro
nvd
CVE-2020-0217P3CRITICALCVSS 9.8v10.0vAndroid-102020-06-11
CVE-2020-0217 [CRITICAL] CWE-787 CVE-2020-0217: In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141331405
nvd
CVE-2023-21096P3CRITICALCVSS 9.8v12.0v12.1+2 more2023-04-19
CVE-2023-21096 [CRITICAL] CWE-416 CVE-2023-21096: In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remo In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-254774758
nvd
CVE-2022-25818P3CRITICALCVSS 9.8v12.02022-03-10
CVE-2022-25818 [CRITICAL] CWE-20 CVE-2022-25818: Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
nvd
CVE-2023-21228P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-21228 [CRITICAL] CVE-2023-21228: In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21218P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-21218 [CRITICAL] CVE-2023-21218: In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21263P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-21263 [CRITICAL] CVE-2023-21263: In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught excep In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21217P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-21217 [CRITICAL] CVE-2023-21217: In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. Th In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9467P3CRITICALCVSS 9.8v7.0v7.1.1+9 more2024-11-20
CVE-2018-9467 [CRITICAL] CWE-276 CVE-2018-9467: In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determin In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20078P3CRITICALCVSS 9.8v12.0v13.0+1 more2024-07-01
CVE-2024-20078 [CRITICAL] CWE-843 CVE-2024-20078: In venc, there is a possible out of bounds write due to type confusion. This could lead to local esc In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.
nvd
CVE-2025-22435P3CRITICALCVSS 9.8v13.0v14.0+4 more2025-09-02
CVE-2025-22435 [CRITICAL] CWE-843 CVE-2025-22435: In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This co In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32911P3CRITICALCVSS 9.8vAndroid kernel2024-06-13
CVE-2024-32911 [CRITICAL] CWE-327 CVE-2024-32911: There is a possible escalation of privilege due to improperly used crypto. This could lead to remote There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21282P3HIGHCVSS 8.8v11.0v12.0+6 more2023-08-14
CVE-2023-21282 [HIGH] CWE-787 CVE-2023-21282: In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bo In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48609P3CRITICALCVSS 9.1v14.0v15.0+4 more2026-03-02
CVE-2025-48609 [CRITICAL] CWE-400 CVE-2025-48609: In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43767P3HIGHCVSS 8.8v12.0v12.1+8 more2025-01-03
CVE-2024-43767 [HIGH] CWE-94 CVE-2024-43767: In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to i In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32925P3HIGHCVSS 8.8vAndroid kernel2024-06-13
CVE-2024-32925 [HIGH] CWE-787 CVE-2024-32925: In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missi In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0084P3HIGHCVSS 8.8v13.0v14.0+4 more2025-08-26
CVE-2025-0084 [HIGH] CWE-416 CVE-2025-0084: In multiple locations, there is a possible out of bounds write due to a use after free. This could l In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase