cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 125 of 339
CVE-2022-36858P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36858 [HIGH] CWE-122 CVE-2022-36858: A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognition A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36845P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36845 [HIGH] CWE-122 CVE-2022-36845: A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk. A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36863P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36863 [HIGH] CWE-122 CVE-2022-36863: A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionTe A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36846P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36846 [HIGH] CWE-122 CVE-2022-36846: A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36843P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36843 [HIGH] CWE-122 CVE-2022-36843: A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk. A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36842P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36842 [HIGH] CWE-122 CVE-2022-36842: A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36841P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36841 [HIGH] CWE-122 CVE-2022-36841: A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.sp A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-36860P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-36860 [HIGH] CWE-122 CVE-2022-36860: A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.sam A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2022-25814P3HIGHCVSS 7.8v11.0v12.02022-03-10
CVE-2022-25814 [HIGH] CWE-276 CVE-2022-25814: PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
nvd
CVE-2021-39669P3HIGHCVSS 7.8v11.0v12.0+1 more2022-02-11
CVE-2021-39669 [HIGH] CWE-1021 CVE-2021-39669: In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12
nvd
CVE-2022-33703P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-12
CVE-2022-33703 [HIGH] CWE-20 CVE-2022-33703: Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attack Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2022-39883P3HIGHCVSS 7.8v10.0v11.0+1 more2022-11-09
CVE-2022-39883 [HIGH] CWE-285 CVE-2022-39883: Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
nvd
CVE-2014-7921P3CRITICALCVSS 9.8v4.0.3v4.0.4+15 more2017-04-13
CVE-2014-7921 [CRITICAL] CVE-2014-7921: mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.
nvd
CVE-2019-2008P3HIGHCVSS 7.5v8.0v8.1+2 more2019-06-19
CVE-2019-2008 [HIGH] CWE-362 CVE-2019-2008: In createEffect of AudioFlinger.cpp, there is a possible memory corruption due to a race condition. In createEffect of AudioFlinger.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-122309228
nvd
CVE-2017-11052P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11052 [HIGH] CWE-125 CVE-2017-11052: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_NDP cfg80211 vendor command a buffer over-read can occur.
nvd
CVE-2017-11054P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11054 [HIGH] CWE-125 CVE-2017-11054: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.
nvd
CVE-2017-11051P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11051 [HIGH] CWE-200 CVE-2017-11051: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, information disclosure is possible in function __wlan_hdd_cfg80211_testmode since buffer hb_params is not initialized to zero.
nvd
CVE-2017-11061P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11061 [HIGH] CWE-125 CVE-2017-11061: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing cfg80211 vendor sub command QCA_NL80211_VENDOR_SUBCMD_ROAM, a buffer over-read can occur.
nvd
CVE-2017-11055P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11055 [HIGH] CWE-125 CVE-2017-11055: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION cfg80211 vendor command, a buffer over-read can occur.
nvd
CVE-2020-26606P3HIGHCVSS 7.5v8.0v8.1+3 more2020-10-06
CVE-2020-26606 [HIGH] CVE-2020-26606: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. An attacker can access certain Secure Folder content via a debugging command. The Samsung ID is SVE-2020-18673 (October 2020).
nvd
Google Android vulnerabilities | cvebase