Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 128 of 339
CVE-2016-0849P3HIGHCVSS 8.4v5.0v5.0.1+4 more2016-04-18
CVE-2016-0849 [HIGH] CWE-189 CVE-2016-0849: Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0
Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26960931.
nvd
CVE-2016-0806P3HIGHCVSS 8.4v4.0v4.0.1+22 more2016-02-07
CVE-2016-0806 [HIGH] CWE-264 CVE-2016-0806: The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.
The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25344453.
nvd
CVE-2018-15835P3HIGHCVSS 7.5≥ 1.0, ≤ 9.02018-11-30
CVE-2018-15835 [HIGH] CWE-732 CVE-2018-15835: Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
nvd
CVE-2016-3885P3HIGHCVSS 7.8v5.0v5.0.1+5 more2016-09-11
CVE-2016-3885 [HIGH] CWE-264 CVE-2016-3885: debuggerd/debuggerd.cpp in Debuggerd in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2
debuggerd/debuggerd.cpp in Debuggerd in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles the interaction between PTRACE_ATTACH operations and thread exits, which allows attackers to gain privileges via a crafted application, aka internal bug 29555636.
nvd
CVE-2017-0806P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-10-04
CVE-2017-0806 [HIGH] CWE-502 CVE-2017-0806: An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Andr
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.
nvd
CVE-2016-2505P3HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2016-2505 [HIGH] CWE-119 CVE-2016-2505: mpeg2ts/ATSParser.cpp in libstagefright in mediaserver in Android 6.x before 2016-07-01 does not val
mpeg2ts/ATSParser.cpp in libstagefright in mediaserver in Android 6.x before 2016-07-01 does not validate a certain section length, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28333006.
nvd
CVE-2016-6492P3HIGHCVSS 7.8≤ 7.1.02017-01-12
CVE-2016-6492 [HIGH] CWE-264 CVE-2016-6492: The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local user
The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges via a crafted application that makes an MT6573FDVTIOC_T_SET_FDCONF_CMD IOCTL call.
nvd
CVE-2017-13194P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13194 [HIGH] CWE-20 CVE-2017-13194: A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.
nvd
CVE-2017-0750P3HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0750 [HIGH] CWE-787 CVE-2017-0750: A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions
A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.
nvd
CVE-2016-6762P3HIGHCVSS 7.8v5.0v5.0.1+7 more2017-01-12
CVE-2016-6762 [HIGH] CWE-264 CVE-2016-6762: An elevation of privilege vulnerability in the libziparchive library could enable a local malicious
An elevation of privilege vulnerability in the libziparchive library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: A
nvd
CVE-2016-3874P3HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3874 [HIGH] CWE-264 CVE-2016-3874: CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-09-05 on Nexus 5X d
CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-09-05 on Nexus 5X devices does not properly validate the arguments array, which allows attackers to gain privileges via a crafted application that sends a WE_UNIT_TEST_CMD command, aka Android internal bug 29944562 and Qualcomm internal bug CR997797.
nvd
CVE-2017-0545P3HIGHCVSS 7.8v5.0v5.0.1+9 more2017-04-07
CVE-2017-0545 [HIGH] CWE-682 CVE-2017-0545: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2016-2476P3HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2476 [HIGH] CWE-119 CVE-2016-2476: mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27207275.
nvd
CVE-2017-0387P3HIGHCVSS 7.8v5.0v5.0.1+8 more2017-01-12
CVE-2017-0387 [HIGH] CVE-2017-0387: An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to
An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0
nvd
CVE-2016-6706P3HIGHCVSS 7.8≤ 7.02016-12-13
CVE-2016-6706 [HIGH] CWE-264 CVE-2016-6706: An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-
An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to
nvd
CVE-2016-6742P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6742 [HIGH] CWE-264 CVE-2016-6742: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-1
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30799828.
nvd
CVE-2016-6745P3HIGHCVSS 7.8≤ 7.1.0v7.02016-11-25
CVE-2016-6745 [HIGH] CWE-264 CVE-2016-6745: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-1
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-31252388.
nvd
CVE-2016-6744P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6744 [HIGH] CWE-264 CVE-2016-6744: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-1
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30970485.
nvd
CVE-2017-0383P3HIGHCVSS 7.8v7.0v7.1.02017-01-12
CVE-2017-0383 [HIGH] CWE-190 CVE-2017-0383: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd
CVE-2017-0385P3HIGHCVSS 7.8v4.0v4.0.1+25 more2017-01-12
CVE-2017-0385 [HIGH] CVE-2017-0385: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd