Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 129 of 339
CVE-2016-2067P3HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2016-2067 [HIGH] CWE-269 CVE-2016-2067: drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used
drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging accidental read-write mappings, aka Qualcomm internal bu
nvd
CVE-2016-6743P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6743 [HIGH] CWE-264 CVE-2016-6743: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-1
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30937462.
nvd
CVE-2014-9803P3HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9803 [HIGH] CWE-19 CVE-2014-9803: arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Andro
arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28557020.
nvd
CVE-2014-9795P3HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9795 [HIGH] CVE-2014-9795: app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices does no
app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices does not properly check for an integer overflow, which allows attackers to bypass intended access restrictions via crafted start and size values, aka Android internal bug 28820720 and Qualcomm internal bug CR681957, a related issue to CVE-2014-4325.
nvd
CVE-2016-3909P3HIGHCVSS 7.8v4.0v4.0.1+21 more2016-10-10
CVE-2016-3909 [HIGH] CWE-264 CVE-2016-3909: The SoftMPEG4 component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5
The SoftMPEG4 component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30033990.
nvd
CVE-2019-2132P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2132 [HIGH] CVE-2019-2132: It is possible to overlay the VPN dialog by a malicious application. This could lead to local escala
It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-130568701.
nvd
CVE-2019-2131P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2131 [HIGH] CWE-1188 CVE-2019-2131: An application with overlay permission can display overlays on top of settings UI. This could lead t
An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-119115683.
nvd
CVE-2016-5342P3HIGHCVSS 7.8≤ 7.02016-08-30
CVE-2016-5342 [HIGH] CWE-787 CVE-2016-5342: Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan
Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service or possibly have unspecified other impact by
nvd
CVE-2016-2060P3HIGHCVSS 7.8≤ 6.0.12016-05-09
CVE-2016-2060 [HIGH] CWE-264 CVE-2016-2060: server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innova
server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access restrictions via a crafted application.
nvd
CVE-2020-12751P3HIGHCVSS 7.8v8.0v8.1+2 more2020-05-11
CVE-2020-12751 [HIGH] CWE-787 CVE-2020-12751: An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Qur
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung ID is SVE-2020-16943 (May 2020).
nvd
CVE-2017-0794P3HIGHCVSS 7.8≤ 8.02017-09-08
CVE-2017-0794 [HIGH] CWE-362 CVE-2017-0794: A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Version
A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. Android ID: A-35644812.
nvd
CVE-2017-0827P3HIGHCVSS 7.8≤ 8.02017-10-04
CVE-2017-0827 [HIGH] CVE-2017-0827: An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Andr
An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-62539960. References: M-ALPS03353876, M-ALPS03353861, M-ALPS03353869, M-ALPS03353867, M-ALPS03353872.
nvd
CVE-2017-0796P3HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0796 [HIGH] CVE-2017-0796: A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: An
A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.
nvd
CVE-2017-0797P3HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0797 [HIGH] CVE-2017-0797: A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android.
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.
nvd
CVE-2017-0795P3HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0795 [HIGH] CVE-2017-0795: A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android.
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36198473. References: M-ALPS03361480.
nvd
CVE-2017-0711P3HIGHCVSS 7.8v7.1.22017-07-06
CVE-2017-0711 [HIGH] CVE-2017-0711: A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions
A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions: Android kernel. Android ID: A-36099953. References: M-ALPS03206781.
nvd
CVE-2020-0366P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0366 [HIGH] CWE-1021 CVE-2020-0366: In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This
In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-138443815
nvd
CVE-2017-0803P3HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0803 [HIGH] CVE-2017-0803: A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android.
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36136137. References: M-ALPS03361477.
nvd
CVE-2017-0804P3HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0804 [HIGH] CVE-2017-0804: A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Andro
A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Android kernel. Android ID: A-36274676. References: M-ALPS03361487.
nvd
CVE-2017-0741P3HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0741 [HIGH] CVE-2017-0741: A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Andro
A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Android kernel. Android ID: A-32458601. References: M-ALPS03007523.
nvd