Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 116 of 339
CVE-2019-2031P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-04-19
CVE-2019-2031 [HIGH] CWE-787 CVE-2019-2031: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a mi
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8
nvd
CVE-2018-5907P3HIGHCVSS 7.8≤ 8.12018-07-06
CVE-2018-5907 [HIGH] CWE-190 CVE-2018-5907: Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-pro
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
nvd
CVE-2017-13287P3HIGHCVSS 7.8v6.0v7.0+4 more2018-04-04
CVE-2017-13287 [HIGH] CWE-20 CVE-2017-13287: In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to
In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to local escalation of privilege if mPayload in writeToParcel were null, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0,
nvd
CVE-2018-9558P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-12-06
CVE-2018-9558 [HIGH] CWE-787 CVE-2018-9558: In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a miss
In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC kernel with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8
nvd
CVE-2017-11048P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11048 [HIGH] CWE-416 CVE-2017-11048: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a display driver function, a Use After Free condition can occur.
nvd
CVE-2018-9545P3HIGHCVSS 7.8v9.02018-11-14
CVE-2018-9545 [HIGH] CWE-787 CVE-2018-9545: In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bound
In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113111784
nvd
CVE-2019-2217P3HIGHCVSS 7.8v10.0vAndroid-102019-12-06
CVE-2019-2217 [HIGH] CWE-416 CVE-2019-2217: In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. T
In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141003796
nvd
CVE-2019-9290P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9290 [HIGH] CWE-763 CVE-2019-9290: In tzdata there is possible memory corruption due to a mismatch between allocation and deallocation
In tzdata there is possible memory corruption due to a mismatch between allocation and deallocation functions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113039724
nvd
CVE-2018-11304P3HIGHCVSS 7.8≤ 8.12018-07-06
CVE-2018-11304 [HIGH] CWE-190 CVE-2018-11304: Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-pro
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
nvd
CVE-2019-2173P3HIGHCVSS 7.8v7.1.1v7.1.2+4 more2019-10-11
CVE-2019-2173 [HIGH] CWE-276 CVE-2019-2173: In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due t
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1
nvd
CVE-2018-9560P3HIGHCVSS 7.8v9.02018-12-06
CVE-2018-9560 [HIGH] CWE-787 CVE-2018-9560: In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds
In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth service with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-79946737.
nvd
CVE-2017-9714P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-9714 [HIGH] CWE-119 CVE-2017-9714: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an out of bound memory access may happen in limCheckRxRSNIeMatch in case incorrect RSNIE is received from the client in assoc request.
nvd
CVE-2020-0079P3HIGHCVSS 7.8v9.0v10.0+1 more2020-04-17
CVE-2020-0079 [HIGH] CWE-787 CVE-2020-0079: In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. Th
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144506242
nvd
CVE-2019-9350P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9350 [HIGH] CWE-416 CVE-2019-9350: In Keymaster, there is a possible EoP due to a use after free. This could lead to local escalation o
In Keymaster, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-129562815
nvd
CVE-2019-9258P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9258 [HIGH] CWE-787 CVE-2019-9258: In wifilogd, there is a possible out of bounds write due to a missing bounds check. This could lead
In wifilogd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113655028
nvd
CVE-2019-2112P3HIGHCVSS 7.8v8.0v8.1+2 more2019-07-08
CVE-2019-2112 [HIGH] CWE-416 CVE-2019-2112: In several functions of alarm.cc, there is possible memory corruption due to a use after free. This
In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-117997080.
nvd
CVE-2019-2098P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2098 [HIGH] CWE-862 CVE-2019-2098: In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permiss
In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could lead to local escalation of privilege, with no additional privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 An
nvd
CVE-2019-2092P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2092 [HIGH] CWE-862 CVE-2019-2092: In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permiss
In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2
nvd
CVE-2019-2091P3HIGHCVSS 7.8v7.0v7.1.1+3 more2019-06-07
CVE-2019-2091 [HIGH] CWE-862 CVE-2019-2091: In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible
In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-
nvd
CVE-2017-9687P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-9687 [HIGH] CWE-415 CVE-2017-9687: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can write the value of "0" to the debugfs file that controls ipa ipc log which will lead to the double-free in ipc_log_context_destroy(). Another issue is the Use-After-Free which can happen due to the race con
nvd