Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 114 of 339
CVE-2016-6729P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6729 [HIGH] CWE-264 CVE-2016-6729: An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 coul
An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair t
nvd
CVE-2016-8423P3HIGHCVSS 7.8≤ 7.1.02017-01-12
CVE-2016-8423 [HIGH] CWE-264 CVE-2016-8423: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-8422P3HIGHCVSS 7.8≤ 7.1.02017-01-12
CVE-2016-8422 [HIGH] CWE-264 CVE-2016-8422: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android.
nvd
CVE-2016-10276P3HIGHCVSS 7.8≤ 7.1.22017-05-12
CVE-2016-10276 [HIGH] CWE-264 CVE-2016-10276: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious ap
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android
nvd
CVE-2017-13251P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13251 [HIGH] CWE-787 CVE-2017-13251: In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to
In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when running multi threaded with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8
nvd
CVE-2019-2134P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2134 [HIGH] CWE-190 CVE-2019-2134: In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due
In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-
nvd
CVE-2020-0478P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0478 [HIGH] CWE-787 CVE-2020-0478: In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bou
In extend_frame_lowbd of restoration.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150780418
nvd
CVE-2020-0360P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0360 [HIGH] CVE-2020-0360: In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consen
In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145129456
nvd
CVE-2020-0319P3HIGHCVSS 7.8v11.0vAndroid-112020-09-18
CVE-2020-0319 [HIGH] CWE-787 CVE-2020-0319: In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137868765
nvd
CVE-2020-0406P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0406 [HIGH] CWE-787 CVE-2020-0406: In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could le
In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if another exploit allowed this to be triggered with different parameters, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-13
nvd
CVE-2020-27048P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27048 [HIGH] CWE-787 CVE-2020-27048: In RW_SendRawFrame of rw_main.cc, there is a possible out of bounds write due to a missing bounds ch
In RW_SendRawFrame of rw_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650117
nvd
CVE-2020-27049P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27049 [HIGH] CWE-787 CVE-2020-27049: In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing boun
In rw_t3t_send_raw_frame of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649467
nvd
CVE-2020-0475P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0475 [HIGH] CWE-862 CVE-2020-0475: In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept
In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162324374
nvd
CVE-2020-0479P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0479 [HIGH] CWE-863 CVE-2020-0479: In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a malicious app to access files available to the DocumentProvider without user permission, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andro
nvd
CVE-2020-0480P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0480 [HIGH] CWE-862 CVE-2020-0480: In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android
nvd
CVE-2021-0600P3HIGHCVSS 7.8v8.1v9.0+3 more2021-07-14
CVE-2021-0600 [HIGH] CWE-20 CVE-2021-0600: In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device a
In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11And
nvd
CVE-2021-39702P3HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39702 [HIGH] CWE-1021 CVE-2021-39702: In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to insta
In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID
nvd
CVE-2021-1036P3HIGHCVSS 7.8v9.0v10.0+3 more2022-01-14
CVE-2021-1036 [HIGH] CWE-1021 CVE-2021-1036: In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/over
In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182812255
nvd
CVE-2021-39764P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39764 [HIGH] CWE-20 CVE-2021-39764: In Settings, there is a possible way to display an incorrect app name due to improper input validati
In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead to local escalation of privilege via app spoofing with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-170642995
nvd
CVE-2021-39780P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39780 [HIGH] CWE-276 CVE-2021-39780: In Traceur, there is a possible bypass of developer settings requirements for capturing system trace
In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204992293
nvd