cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 127 of 339
CVE-2021-1020P3HIGHCVSS 7.3v12.0vAndroid-122021-12-15
CVE-2021-1020 [HIGH] CWE-20 CVE-2021-1020: In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notifi In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195111725
nvd
CVE-2023-45780P3HIGHCVSS 7.3fixed in 14.0≤ 142023-10-30
CVE-2023-45780 [HIGH] CVE-2023-45780: In Print Service, there is a possible background activity launch due to a logic error in the code. T In Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-20137P3HIGHCVSS 7.3v12.0v12.1+1 more2022-06-15
CVE-2022-20137 [HIGH] CWE-862 CVE-2022-20137: In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-2
nvd
CVE-2023-20976P3HIGHCVSS 7.3v13.0vAndroid-132023-03-24
CVE-2023-20976 [HIGH] CWE-20 CVE-2023-20976: In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13And
nvd
CVE-2023-21189P3HIGHCVSS 7.3v13.0vAndroid-132023-06-28
CVE-2023-21189 [HIGH] CWE-667 CVE-2023-21189: In startLockTaskMode of LockTaskController.java, there is a possible bypass of lock task mode due to In startLockTaskMode of LockTaskController.java, there is a possible bypass of lock task mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-213942596
nvd
CVE-2017-18649P3HIGHCVSS 7.2v7.0v7.1.0+2 more2020-04-07
CVE-2017-18649 [HIGH] CWE-354 CVE-2017-18649: An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a devic An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system image, aka the "SamFAIL" issue. The Samsung ID is SVE-2017-10465 (November 2017).
nvd
CVE-2018-9468P3HIGHCVSS 7.1v7.0v7.1.1+9 more2024-11-20
CVE-2018-9468 [HIGH] CVE-2018-9468: In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permiss In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-3858P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3858 [CRITICAL] CWE-264 CVE-2015-3858: The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48 The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.
nvd
CVE-2024-34725P3HIGHCVSS 7.0vAndroid SoC2024-07-09
CVE-2024-34725 [HIGH] CWE-362 CVE-2024-34725: In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-20596P3CRITICALCVSS 9.1v7.0v7.1.0+4 more2020-03-24
CVE-2019-20596 [CRITICAL] CVE-2019-20596: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is information disclosure in the GateKeeper Trustlet. The Samsung ID is SVE-2019-13958 (June 2019).
nvd
CVE-2024-20046P3MEDIUMCVSS 6.6v12.02024-04-01
CVE-2024-20046 [MEDIUM] CWE-190 CVE-2024-20046: In battery, there is a possible escalation of privilege due to an integer overflow. This could lead In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue ID: ALPS08485622.
nvd
CVE-2025-48631P3MEDIUMCVSS 6.5v13.0v14.0+6 more2025-12-08
CVE-2025-48631 [MEDIUM] CWE-400 CVE-2025-48631: In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0080P3MEDIUMCVSS 6.5v14.0v15.0+8 more2026-06-01
CVE-2026-0080 [MEDIUM] CWE-190 CVE-2026-0080: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0040P3MEDIUMCVSS 6.5v14.0v15.0+8 more2026-06-01
CVE-2026-0040 [MEDIUM] CWE-190 CVE-2026-0040: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0051P3MEDIUMCVSS 6.5v14.0v15.0+8 more2026-06-01
CVE-2026-0051 [MEDIUM] CWE-20 CVE-2026-0051: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0044P3MEDIUMCVSS 6.5v14.0v15.0+8 more2026-06-01
CVE-2026-0044 [MEDIUM] CWE-190 CVE-2026-0044: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0052P3MEDIUMCVSS 6.5v14.0v15.0+8 more2026-06-01
CVE-2026-0052 [MEDIUM] CWE-190 CVE-2026-0052: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3748P3HIGHCVSS 8.4v6.0v6.0.12016-07-11
CVE-2016-3748 [HIGH] CWE-264 CVE-2016-3748: The sockets subsystem in Android 6.x before 2016-07-01 allows attackers to bypass intended system-ca The sockets subsystem in Android 6.x before 2016-07-01 allows attackers to bypass intended system-call restrictions via a crafted application that makes an ioctl call, aka internal bug 28171804.
nvd
CVE-2016-2431P3HIGHCVSS 7.8≤ 6.0.12016-05-09
CVE-2016-2431 [HIGH] CWE-264 CVE-2016-2431: The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), a The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 24968809.
nvd
CVE-2016-0847P3HIGHCVSS 8.4v5.0v5.0.1+4 more2016-04-18
CVE-2016-0847 [HIGH] CWE-264 CVE-2016-0847: The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 a The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephone number of a call via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26864502.
nvd
Google Android vulnerabilities | cvebase