cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 113 of 339
CVE-2017-0503P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0503 [HIGH] CVE-2017-0503: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2016-3843P3HIGHCVSS 7.8≤ 6.0.12016-08-05
CVE-2016-3843 [HIGH] CWE-264 CVE-2016-3843: Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allow Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka Android internal bugs 28086229 and 29119870 and Qualcomm internal bug CR1011071.
nvd
CVE-2017-0509P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0509 [HIGH] CVE-2017-0509: An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Version
nvd
CVE-2017-0502P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0502 [HIGH] CVE-2017-0502: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0501P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0501 [HIGH] CVE-2017-0501: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0500P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0500 [HIGH] CVE-2017-0500: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0506P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0506 [HIGH] CVE-2017-0506: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0740P3HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0740 [HIGH] CVE-2017-0740: A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.
nvd
CVE-2017-0713P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-09
CVE-2017-0713 [HIGH] CVE-2017-0713: A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.
nvd
CVE-2021-0339P3HIGHCVSS 7.8v8.1v9.0+2 more2021-02-10
CVE-2021-0339 [HIGH] CWE-754 CVE-2021-0339: In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Androi
nvd
CVE-2017-0331P3HIGHCVSS 7.8≤ 7.1.12017-05-02
CVE-2017-0331 [HIGH] CWE-367 CVE-2017-0331: An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious ap An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2017-6247P3HIGHCVSS 7.8v7.1.22017-07-06
CVE-2017-6247 [HIGH] CVE-2017-6247: An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious ap An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of local arbitrary code execution in a privileged process in the kernel. Product: Android. Versions: N/A. Android ID: A-34386301. References:
nvd
CVE-2021-39692P3HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39692 [HIGH] CWE-1021 CVE-2021-39692: In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing u In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-
nvd
CVE-2016-6735P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6735 [HIGH] CWE-264 CVE-2016-6735: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2016-6734P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6734 [HIGH] CWE-264 CVE-2016-6734: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2017-0522P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0522 [HIGH] CVE-2017-0522: An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application An elevation of privilege vulnerability in a MediaTek APK could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High due to the possibility of local arbitrary code execution in a privileged process. Product: Android. Versions: N/A. Android ID: A-32916158. References: M-ALPS0303251
nvd
CVE-2016-8436P3HIGHCVSS 7.8≤ 6.0.12017-01-12
CVE-2016-8436 [HIGH] CWE-264 CVE-2016-8436: An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-10275P3HIGHCVSS 7.8≤ 7.1.22017-05-12
CVE-2016-10275 [HIGH] CWE-264 CVE-2016-10275: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android
nvd
CVE-2021-0391P3HIGHCVSS 7.8v8.1v9.0+3 more2021-03-10
CVE-2021-0391 [HIGH] CWE-1021 CVE-2021-0391: In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence o In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, without permissions, due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 An
nvd
CVE-2016-6736P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6736 [HIGH] CWE-264 CVE-2016-6736: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
Google Android vulnerabilities | cvebase