cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 123 of 339
CVE-2020-27059P3HIGHCVSS 7.8v8.0v8.1+7 more2021-01-11
CVE-2020-27059 [HIGH] CWE-1021 CVE-2020-27059: In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesti In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, And
nvd
CVE-2021-0317P3HIGHCVSS 7.8v8.0v8.1+8 more2021-01-11
CVE-2021-0317 [HIGH] CWE-863 CVE-2021-0317: In createOrUpdate of Permission.java and related code, there is possible permission escalation due t In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android
nvd
CVE-2016-3826P3HIGHCVSS 7.8v4.0v4.0.1+20 more2016-08-05
CVE-2016-3826 [HIGH] CWE-20 CVE-2016-3826: services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5. services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not validate the reply size for an AudioFlinger effect command, which allows attackers to gain privileges via a crafted application, aka internal bug 29251553.
nvd
CVE-2020-0216P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0216 [HIGH] CWE-190 CVE-2020-0216: In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-126204073
nvd
CVE-2020-0345P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0345 [HIGH] CWE-610 CVE-2020-0345: In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to l In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144286721
nvd
CVE-2021-25414P3HIGHCVSS 7.8v9.0v10.0+1 more2021-06-11
CVE-2021-25414 [HIGH] CWE-20 CVE-2021-25414: Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.
nvd
CVE-2017-13231P3HIGHCVSS 7.8v8.0v8.12018-02-12
CVE-2017-13231 [HIGH] CWE-787 CVE-2017-13231: In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-67962232.
nvd
CVE-2019-20591P3HIGHCVSS 7.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20591 [HIGH] CWE-89 CVE-2019-20591: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Content Provider. The Samsung ID is SVE-2019-14058 (July 2019).
nvd
CVE-2019-20573P3HIGHCVSS 7.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20573 [HIGH] CWE-89 CVE-2019-20573: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider. The Samsung IDs are SVE-2019-14059, SVE-2019-14685 (August 2019).
nvd
CVE-2018-9538P3HIGHCVSS 7.8v8.1v9.02018-12-06
CVE-2018-9538 [HIGH] CWE-125 CVE-2018-9538: In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a po In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions:
nvd
CVE-2018-9559P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-12-06
CVE-2018-9559 [HIGH] CWE-787 CVE-2018-9559: In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due t In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due to an uncaught error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-
nvd
CVE-2017-0842P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-11-16
CVE-2017-0842 [HIGH] CWE-119 CVE-2017-0842: An elevation of privilege vulnerability in the Android system (bluetooth). Product: Android. Version An elevation of privilege vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37502513.
nvd
CVE-2017-11050P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11050 [HIGH] CWE-119 CVE-2017-11050: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when the pktlogconf tool gives a pktlog buffer of size less than the minimal possible source data size in the host driver, a buffer overflow can potentially occur.
nvd
CVE-2020-0024P3HIGHCVSS 7.8v8.0v8.1+3 more2020-05-14
CVE-2020-0024 [HIGH] CWE-276 CVE-2020-0024: In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-137015
nvd
CVE-2022-27826P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-27826 [HIGH] CWE-20 CVE-2022-27826: Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows att Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2019-20770P3HIGHCVSS 7.8v9.02020-04-17
CVE-2019-20770 [HIGH] CWE-120 CVE-2019-20770: An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buf An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buffer overflow that leads to arbitrary code execution. The LG ID is LVE-SMP-190013 (September 2019).
nvd
CVE-2020-10838P3HIGHCVSS 7.8v9.0v10.02020-03-24
CVE-2020-10838 [HIGH] CWE-416 CVE-2020-10838: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a u An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).
nvd
CVE-2017-13212P3HIGHCVSS 7.8v5.1.1v6.0+5 more2018-01-12
CVE-2017-13212 [HIGH] CVE-2017-13212: An elevation of privilege vulnerability in the Android system (systemui). Product: Android. Versions An elevation of privilege vulnerability in the Android system (systemui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187985.
nvd
CVE-2017-11046P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11046 [HIGH] CWE-787 CVE-2017-11046: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when an audio driver ioctl handler is called, a kernel out-of-bounds write can potentially occur.
nvd
CVE-2017-9706P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-9706 [HIGH] CWE-119 CVE-2017-9706: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an array out-of-bounds access can potentially occur in a display driver.
nvd
Google Android vulnerabilities | cvebase