cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 126 of 339
CVE-2022-20302P3HIGHCVSS 7.6v13.0vAndroid-132022-08-12
CVE-2022-20302 [HIGH] CVE-2022-20302: In Settings, there is a possible way to bypass factory reset protections due to a sandbox escape. Th In Settings, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200746457
nvd
CVE-2021-39677P3HIGHCVSS 7.5v11.0vAndroid-112022-02-11
CVE-2021-39677 [HIGH] CWE-125 CVE-2021-39677: In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘ In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-11Android ID: A-205097028
nvd
CVE-2019-20601P3HIGHCVSS 7.5v7.0v7.1.0+5 more2020-03-24
CVE-2019-20601 [HIGH] CWE-787 CVE-2019-20601: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos7570, 7580, An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos7570, 7580, 7870, 7880, and 8890 chipsets) software. RKP memory corruption causes an arbitrary write to protected memory. The Samsung ID is SVE-2019-13921-2 (May 2019).
nvd
CVE-2018-21063P3CRITICALCVSS 9.8v6.0v7.0+5 more2020-04-08
CVE-2018-21063 [CRITICAL] CVE-2018-21063: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) (Exynos chipsets) An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) (Exynos chipsets) software. Keymaster has an architectural problem because tlApi in TEE is not properly protected. The Samsung ID is SVE-2018-11792 (August 2018).
nvd
CVE-2021-25516P3HIGHCVSS 7.5v9.0v10.0+1 more2021-12-08
CVE-2021-25516 [HIGH] CWE-703 CVE-2021-25516: An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Rel An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.
nvd
CVE-2019-20561P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20561 [CRITICAL] CWE-190 CVE-2019-20561: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. The bootloader has an integer signedness error. The Samsung ID is SVE-2019-15230 (October 2019).
nvd
CVE-2022-36853P3HIGHCVSS 7.5v10.0v11.0+1 more2022-09-09
CVE-2022-36853 [HIGH] CWE-20 CVE-2022-36853: Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.
nvd
CVE-2019-20777P3CRITICALCVSS 9.8v7.0v7.1+4 more2020-04-17
CVE-2019-20777 [CRITICAL] CVE-2019-20777: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 softwa An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService mishandles OTA Provisioning on V40 and G7 devices. The LG ID is LVE-SMP-190006 (July 2019).
nvd
CVE-2017-18696P3CRITICALCVSS 9.8v6.0v7.02020-04-07
CVE-2017-18696 [CRITICAL] CWE-119 CVE-2017-18696: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or MSM8996 chipsets) software. RKP allows memory corruption. The Samsung ID is SVE-2016-7897 (January 2017).
nvd
CVE-2017-18691P3CRITICALCVSS 9.8v6.0v7.02020-04-07
CVE-2017-18691 [CRITICAL] CWE-120 CVE-2017-18691: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos8890 chipsets) softw An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos8890 chipsets) software. There are multiple Buffer Overflows in TSP sysfs cmd_store. The Samsung ID is SVE-2016-7500 (January 2017).
nvd
CVE-2016-6731P3HIGHCVSS 7.3≤ 7.02016-11-25
CVE-2016-6731 [HIGH] CWE-264 CVE-2016-6731: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2016-6733P3HIGHCVSS 7.3≤ 7.02016-11-25
CVE-2016-6733 [HIGH] CWE-264 CVE-2016-6733: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2016-6732P3HIGHCVSS 7.3≤ 7.02016-11-25
CVE-2016-6732 [HIGH] CWE-264 CVE-2016-6732: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2016-6730P3HIGHCVSS 7.3≤ 7.02016-11-25
CVE-2016-6730 [HIGH] CWE-264 CVE-2016-6730: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the
nvd
CVE-2015-3843P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3843 [CRITICAL] CWE-264 CVE-2015-3843: The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM commands via an application that sends a crafted Intent, related to com/android/internal/telephony/cat/AppInterface.java, aka internal bug 21697171.
nvd
CVE-2018-21071P3HIGHCVSS 7.3v6.02020-04-08
CVE-2018-21071 [HIGH] CWE-200 CVE-2018-21071: An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected in An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected intent, an attacker can read arbitrary files and emails, and take over an email account. The Samsung ID is SVE-2018-11633 (May 2018).
nvd
CVE-2021-0333P3HIGHCVSS 7.3v8.1v9.0+3 more2021-02-10
CVE-2021-0333 [HIGH] CWE-1021 CVE-2021-0333: In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tap In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVers
nvd
CVE-2023-20921P3HIGHCVSS 7.3v10.0v11.0+4 more2023-01-26
CVE-2023-20921 [HIGH] CWE-670 CVE-2023-20921: In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically gra In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Andr
nvd
CVE-2021-0954P3HIGHCVSS 7.3v10.0v11.0+1 more2021-12-15
CVE-2021-0954 [HIGH] CWE-1021 CVE-2021-0954: In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-143559931
nvd
CVE-2021-1021P3HIGHCVSS 7.3v12.0vAndroid-122021-12-15
CVE-2021-1021 [HIGH] CWE-20 CVE-2021-1021: In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable noti In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195031703
nvd
Google Android vulnerabilities | cvebase