cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 119 of 339
CVE-2022-30717P3HIGHCVSS 7.5v10.0v11.02022-06-07
CVE-2022-30717 [HIGH] CWE-285 CVE-2022-30717: Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to u Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.
nvd
CVE-2019-20780P3CRITICALCVSS 9.8v7.0v7.1+3 more2020-04-17
CVE-2019-20780 [CRITICAL] CWE-427 CVE-2019-20780: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. C An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April 2019).
nvd
CVE-2020-13831P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-06-04
CVE-2020-13831 [CRITICAL] CWE-119 CVE-2020-13831: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) soft An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020).
nvd
CVE-2019-20553P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20553 [CRITICAL] CVE-2019-20553: An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos7885, exynos9610, and exynos9820 chipsets) software. Arbitrary memory read and write operations can occur in RKP. The Samsung ID is SVE-2019-15143 (October 2019).
nvd
CVE-2017-18644P3CRITICALCVSS 9.8v5.1v6.0+5 more2020-04-08
CVE-2017-18644 [CRITICAL] CWE-787 CVE-2017-18644: An issue was discovered on Samsung mobile devices with L(5.1), M(6.x), and N(7.x) software. There is An issue was discovered on Samsung mobile devices with L(5.1), M(6.x), and N(7.x) software. There is a muic_set_reg_sel heap-based buffer overflow during the reading of MUIC register values. The Samsung ID is SVE-2017-10011 (December 2017).
nvd
CVE-2017-18690P3CRITICALCVSS 9.8v4.4v5.0+3 more2020-04-07
CVE-2017-18690 [CRITICAL] CWE-120 CVE-2017-18690: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) (Exyn An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) (Exynos54xx, Exynos7420, Exynos8890, or Exynos8895 chipsets) software. There is a buffer overflow in the sensor hub. The Samsung ID is SVE-2016-7484 (January 2017).
nvd
CVE-2017-18693P3CRITICALCVSS 9.8v4.4v5.0+3 more2020-04-07
CVE-2017-18693 [CRITICAL] CWE-120 CVE-2017-18693: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) softw An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. There is a buffer overflow in the fps sysfs entry. The Samsung ID is SVE-2016-7510 (January 2017).
nvd
CVE-2016-11033P3CRITICALCVSS 9.8v6.02020-04-07
CVE-2016-11033 [CRITICAL] CWE-787 CVE-2016-11033: An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer overflow in tlc_server. The Samsung IDs are SVE-2016-7220 and SVE-2016-7225 (November 2016).
nvd
CVE-2019-20578P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20578 [CRITICAL] CWE-120 CVE-2019-20578: An issue was discovered on Samsung mobile devices with P(9.0) (Exynos 9820 chipsets) software. A Buf An issue was discovered on Samsung mobile devices with P(9.0) (Exynos 9820 chipsets) software. A Buffer overflow occurs when loading the UH Partition during Secure Boot. The Samsung ID is SVE-2019-14412 (August 2019).
nvd
CVE-2019-20558P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20558 [CRITICAL] CWE-120 CVE-2019-20558: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a Buffer Overflow in the Touch Screen Driver. The Samsung ID is SVE-2019-14990 (October 2019).
nvd
CVE-2016-11036P3CRITICALCVSS 9.8v6.02020-04-07
CVE-2016-11036 [CRITICAL] CWE-862 CVE-2016-11036: An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Pro An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).
nvd
CVE-2021-26688P3CRITICALCVSS 9.8v10.02021-02-04
CVE-2021-26688 [CRITICAL] CVE-2021-26688: An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).
nvd
CVE-2017-0847P3CRITICALCVSS 9.8v8.02017-11-16
CVE-2017-0847 [CRITICAL] CWE-276 CVE-2017-0847: An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: An An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.
nvd
CVE-2020-13835P3CRITICALCVSS 9.8v8.02020-06-04
CVE-2020-13835 [CRITICAL] CWE-20 CVE-2020-13835: An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeepe An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
nvd
CVE-2020-10849P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-03-24
CVE-2020-10849 [CRITICAL] CWE-307 CVE-2020-10849: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exyn An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-14575 (January 2020).
nvd
CVE-2024-47031P3HIGHCVSS 7.4vAndroid kernel2024-10-25
CVE-2024-47031 [HIGH] CVE-2024-47031: Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.
nvd
CVE-2023-21251P3HIGHCVSS 7.3v11.0v12.0+6 more2023-07-13
CVE-2023-21251 [HIGH] CWE-20 CVE-2023-21251: In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consen In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-31331P3HIGHCVSS 7.3v12.0v12.1+6 more2024-07-09
CVE-2024-31331 [HIGH] CWE-783 CVE-2024-31331: In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Sett In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-31324P3HIGHCVSS 7.3v12.0v12.1+6 more2024-07-09
CVE-2024-31324 [HIGH] CWE-1021 CVE-2024-31324: In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by laun In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode first and then rotating it to landscape mode. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-22419P3HIGHCVSS 7.3v13.0v14.0+4 more2025-09-02
CVE-2025-22419 [HIGH] CWE-1021 CVE-2025-22419: In multiple locations, there is a possible way to mislead the user into enabling malicious phone cal In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvd
Google Android vulnerabilities | cvebase