cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 118 of 339
CVE-2022-27833P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-27833 [HIGH] CWE-20 CVE-2022-27833: Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write b Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
nvd
CVE-2022-20451P3HIGHCVSS 7.8v10.0v11.0+4 more2022-11-08
CVE-2022-20451 [HIGH] CWE-862 CVE-2022-20451: In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a m In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Androi
nvd
CVE-2022-36862P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36862 [HIGH] CWE-122 CVE-2022-36862: A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.sp A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36844P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36844 [HIGH] CWE-122 CVE-2022-36844: A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spen A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2023-21129P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21129 [HIGH] CWE-276 CVE-2023-21129: In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible a In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Andr
nvd
CVE-2023-40114P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-15
CVE-2023-40114 [HIGH] CWE-416 CVE-2023-40114: In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use aft In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-36847P3HIGHCVSS 7.8v10.02022-09-09
CVE-2022-36847 [HIGH] CWE-416 CVE-2022-36847: Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
nvd
CVE-2022-36849P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36849 [HIGH] CWE-416 CVE-2022-36849: Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR S Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
nvd
CVE-2019-9462P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9462 [HIGH] CWE-125 CVE-2019-9462: In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could le In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-91544774
nvd
CVE-2019-9311P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9311 [HIGH] CWE-190 CVE-2019-9311: In Bluetooth, there is a possible crash due to an integer overflow. This could lead to remote denial In Bluetooth, there is a possible crash due to an integer overflow. This could lead to remote denial of service on incoming calls with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79431031
nvd
CVE-2019-9328P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9328 [HIGH] CWE-125 CVE-2019-9328: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111895000
nvd
CVE-2019-9284P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9284 [HIGH] CWE-125 CVE-2019-9284: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111850706
nvd
CVE-2020-12745P3HIGHCVSS 7.5v10.02020-05-11
CVE-2020-12745 [HIGH] CWE-862 CVE-2020-12745: An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the lo An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipboard content via USSD. The Samsung ID is SVE-2019-16556 (May 2020).
nvd
CVE-2016-3744P3HIGHCVSS 7.5v4.0v4.0.1+20 more2016-07-11
CVE-2016-3744 [HIGH] CWE-119 CVE-2016-3744: Buffer overflow in the create_pbuf function in btif/src/btif_hh.c in Bluetooth in Android 4.x before Buffer overflow in the create_pbuf function in btif/src/btif_hh.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows remote attackers to gain privileges via a crafted pairing operation, aka internal bug 27930580.
nvd
CVE-2019-20621P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20621 [CRITICAL] CWE-787 CVE-2019-20621: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).
nvd
CVE-2020-26598P3HIGHCVSS 7.5v8.0v8.1+1 more2020-10-06
CVE-2020-26598 [HIGH] CWE-862 CVE-2020-26598: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized actor to kill a TCP connection. The LG ID is LVE-SMP-200023 (October 2020).
nvd
CVE-2019-20549P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20549 [CRITICAL] CWE-125 CVE-2019-20549: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets) software. A heap out-of-bounds access can occur during LE Packet reception in Broadcom Bluetooth. The Samsung ID is SVE-2019-15724 (November 2019).
nvd
CVE-2017-0829P3CRITICALCVSS 9.8≤ 8.02017-10-04
CVE-2017-0829 [CRITICAL] CVE-2017-0829: An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Andr An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.
nvd
CVE-2024-32902P3HIGHCVSS 7.5vAndroid kernel2024-06-13
CVE-2024-32902 [HIGH] CWE-400 CVE-2024-32902: Remote prevention of access to cellular service with no user interaction (for example, crashing the Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)
nvd
CVE-2023-21419P3HIGHCVSS 7.5v12.02023-02-09
CVE-2023-21419 [HIGH] CWE-287 CVE-2023-21419: An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.
nvd
Google Android vulnerabilities | cvebase