Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 122 of 339
CVE-2016-8433P3HIGHCVSS 7.8≤ 7.1.02017-01-12
CVE-2016-8433 [HIGH] CWE-264 CVE-2016-8433: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious applic
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Vers
nvd
CVE-2017-0604P3HIGHCVSS 7.8≤ 7.1.22017-05-12
CVE-2017-0604 [HIGH] CWE-670 CVE-2017-0604: An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local mal
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product:
nvd
CVE-2016-10274P3HIGHCVSS 7.8≤ 7.1.22017-05-12
CVE-2016-10274 [HIGH] CWE-264 CVE-2016-10274: An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local mali
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product:
nvd
CVE-2017-13252P3HIGHCVSS 7.8v8.0v8.12018-04-04
CVE-2017-13252 [HIGH] CWE-787 CVE-2017-13252: In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input valida
In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input validation that results in a read from uninitialized memory. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-7052
nvd
CVE-2018-9458P3HIGHCVSS 7.8v8.0v8.12018-11-06
CVE-2018-9458 [HIGH] CWE-1021 CVE-2018-9458: In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interc
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypresses while the screen was locked with no additional execution privileges needed. User interaction is needed for explo
nvd
CVE-2019-2099P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2099 [HIGH] CWE-787 CVE-2019-2099: In nfa_rw_store_ndef_rx_buf of nfa_rw_act.cc, there is a possible out-of-bound write due to a missin
In nfa_rw_store_ndef_rx_buf of nfa_rw_act.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Andro
nvd
CVE-2020-0267P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0267 [HIGH] CWE-610 CVE-2020-0267: In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This cou
In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-1
nvd
CVE-2019-2133P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2133 [HIGH] CWE-787 CVE-2019-2133: In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
CVE-2015-1528P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-1528 [CRITICAL] CWE-189 CVE-2015-1528: Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before
Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted application, aka internal bug 19334482.
nvd
CVE-2020-0080P3HIGHCVSS 7.8v10.0vAndroid-102020-04-17
CVE-2020-0080 [HIGH] CVE-2020-0080: In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to di
In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlaying other apps without the notification icon that it's overlaying. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android
nvd
CVE-2019-2034P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-04-19
CVE-2019-2034 [HIGH] CWE-190 CVE-2019-2034: In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overf
In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the NFC process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8
nvd
CVE-2020-0179P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0179 [HIGH] CWE-20 CVE-2020-0179: In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient
In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.Product: AndroidVersions: Android-10Android ID: A-130656917
nvd
CVE-2019-2035P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-04-19
CVE-2019-2035 [HIGH] CWE-787 CVE-2019-2035: In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bound
In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. A
nvd
CVE-2020-0202P3HIGHCVSS 7.8v11.0vAndroid-112020-06-11
CVE-2020-0202 [HIGH] CWE-862 CVE-2020-0202: In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirement
In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-11 Android ID
nvd
CVE-2021-0386P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0386 [HIGH] CWE-1021 CVE-2021-0386: In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default
In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173421110
nvd
CVE-2021-0645P3HIGHCVSS 7.8v11.0vAndroid-112021-08-17
CVE-2021-0645 [HIGH] CWE-863 CVE-2021-0645: In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This
In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional execution privileges needed. User interaction is needed for exploitation.Produc
nvd
CVE-2020-0219P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0219 [HIGH] CWE-476 CVE-2020-0219: In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to
In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-122836081
nvd
CVE-2022-27835P3HIGHCVSS 7.8v12.02022-04-11
CVE-2022-27835 [HIGH] CWE-20 CVE-2022-27835: Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory writ
Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.
nvd
CVE-2021-39790P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39790 [HIGH] CWE-863 CVE-2021-39790: In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permissi
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-186405146
nvd
CVE-2015-6610P3CRITICALCVSS 10.0≥ 5.0, < 5.1.1v6.02015-11-03
CVE-2015-6610 [CRITICAL] CWE-119 CVE-2015-6610: libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain pri
libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka internal bug 23707088.
nvd