cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 114 of 339
CVE-2016-6729P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6729 [HIGH] CWE-264 CVE-2016-6729: An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 coul An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair t
nvd
CVE-2016-8423P3HIGHCVSS 7.8≤ 7.1.02017-01-12
CVE-2016-8423 [HIGH] CWE-264 CVE-2016-8423: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-8422P3HIGHCVSS 7.8≤ 7.1.02017-01-12
CVE-2016-8422 [HIGH] CWE-264 CVE-2016-8422: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-10276P3HIGHCVSS 7.8≤ 7.1.22017-05-12
CVE-2016-10276 [HIGH] CWE-264 CVE-2016-10276: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android
nvd
CVE-2017-13251P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13251 [HIGH] CWE-787 CVE-2017-13251: In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when running multi threaded with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8
nvd
CVE-2019-2134P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2134 [HIGH] CWE-190 CVE-2019-2134: In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-
nvd
CVE-2020-0478P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0478 [HIGH] CWE-787 CVE-2020-0478: In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bou In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150780418
nvd
CVE-2020-0360P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0360 [HIGH] CVE-2020-0360: In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consen In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145129456
nvd
CVE-2020-0319P3HIGHCVSS 7.8v11.0vAndroid-112020-09-18
CVE-2020-0319 [HIGH] CWE-787 CVE-2020-0319: In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137868765
nvd
CVE-2020-0406P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0406 [HIGH] CWE-787 CVE-2020-0406: In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could le In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if another exploit allowed this to be triggered with different parameters, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-13
nvd
CVE-2020-27048P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27048 [HIGH] CWE-787 CVE-2020-27048: In RW_SendRawFrame of rw_main.cc, there is a possible out of bounds write due to a missing bounds ch In RW_SendRawFrame of rw_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650117
nvd
CVE-2020-27049P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27049 [HIGH] CWE-787 CVE-2020-27049: In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing boun In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649467
nvd
CVE-2020-0475P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0475 [HIGH] CWE-862 CVE-2020-0475: In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162324374
nvd
CVE-2020-0479P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0479 [HIGH] CWE-863 CVE-2020-0479: In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andro
nvd
CVE-2020-0480P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0480 [HIGH] CWE-862 CVE-2020-0480: In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android
nvd
CVE-2021-0600P3HIGHCVSS 7.8v8.1v9.0+3 more2021-07-14
CVE-2021-0600 [HIGH] CWE-20 CVE-2021-0600: In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device a In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11And
nvd
CVE-2021-39702P3HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39702 [HIGH] CWE-1021 CVE-2021-39702: In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to insta In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID
nvd
CVE-2021-1036P3HIGHCVSS 7.8v9.0v10.0+3 more2022-01-14
CVE-2021-1036 [HIGH] CWE-1021 CVE-2021-1036: In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/over In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182812255
nvd
CVE-2021-39764P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39764 [HIGH] CWE-20 CVE-2021-39764: In Settings, there is a possible way to display an incorrect app name due to improper input validati In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privilege via app spoofing with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-170642995
nvd
CVE-2021-39780P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39780 [HIGH] CWE-276 CVE-2021-39780: In Traceur, there is a possible bypass of developer settings requirements for capturing system trace In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204992293
nvd
Google Android vulnerabilities | cvebase