cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 13 of 339
CVE-2024-31328P3HIGHCVSS 8.8v14.0v16.0+2 more2026-03-02
CVE-2024-31328 [HIGH] CWE-693 CVE-2024-31328: In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitr In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-3826P3MEDIUMCVSS 5.0≤ 5.12015-10-01
CVE-2015-3826 [MEDIUM] CWE-119 CVE-2015-3826: The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android be The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to cause a denial of service (integer underflow, buffer over-read, and mediaserver process crash) via crafted 3GPP met
nvd
CVE-2019-9278P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-9278 [HIGH] CWE-190 CVE-2019-9278: In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to r In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
nvd
CVE-2019-2204P3CRITICALCVSS 9.8v9.0vAndroid-8.1+1 more2019-11-13
CVE-2019-2204 [CRITICAL] CWE-125 CVE-2019-2204: In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This could lead to remote code execution in the pacprocessor with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.1, Android-9 Android ID: A-138442295
nvd
CVE-2019-2097P3CRITICALCVSS 9.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2097 [CRITICAL] CWE-843 CVE-2019-2097: In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to typ In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This could lead to remote code execution from a malicious proxy configuration, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-
nvd
CVE-2022-27571P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-27571 [CRITICAL] CWE-122 CVE-2022-27571: Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
nvd
CVE-2022-27570P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-27570 [CRITICAL] CWE-122 CVE-2022-27570: Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
nvd
CVE-2019-9301P3CRITICALCVSS 9.8v10.0vAndroid-102019-09-27
CVE-2019-9301 [CRITICAL] CWE-190 CVE-2019-9301: In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663384
nvd
CVE-2023-48425P3CRITICALCVSS 9.8vAndroid SoC2023-12-11
CVE-2023-48425 [CRITICAL] CWE-20 CVE-2023-48425: U-Boot vulnerability resulting in persistent Code Execution U-Boot vulnerability resulting in persistent Code Execution
nvd
CVE-2021-0325P3HIGHCVSS 8.8v8.1v9.0+3 more2021-02-10
CVE-2021-0325 [HIGH] CWE-787 CVE-2021-0325: In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a he In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-174238784
nvd
CVE-2019-1988P3HIGHCVSS 8.8v8.0v8.1+1 more2019-02-28
CVE-2019-1988 [HIGH] CWE-20 CVE-2019-1988: In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validati In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-118372692.
nvd
CVE-2017-7375P3CRITICALCVSS 9.8v4.4.4v5.0.2+6 more2018-02-19
CVE-2017-7375 [CRITICAL] CWE-611 CVE-2017-7375: A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the calle A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expo
nvd
CVE-2014-9902P3CRITICALCVSS 9.8≤ 6.0.12016-08-05
CVE-2014-9902 [CRITICAL] CWE-119 CVE-2014-9902: Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android be Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android internal bug 28668638 and Qualcomm internal bugs CR553937 and CR553941.
nvd
CVE-2025-48593P3HIGHCVSS 8.0v13.0v14.0+6 more2025-11-18
CVE-2025-48593 [HIGH] CWE-416 CVE-2025-48593: In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-27568P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-27568 [CRITICAL] CWE-122 CVE-2022-27568: Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Ap Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
nvd
CVE-2022-26098P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-26098 [CRITICAL] CWE-122 CVE-2022-26098: Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.
nvd
CVE-2022-27569P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-27569 [CRITICAL] CWE-122 CVE-2022-27569: Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Ap Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
nvd
CVE-2022-27572P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-27572 [CRITICAL] CWE-122 CVE-2022-27572: Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Ap Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.
nvd
CVE-2021-25346P3CRITICALCVSS 9.8v8.0v8.1+2 more2021-03-04
CVE-2021-25346 [CRITICAL] CWE-787 CVE-2021-25346: A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.
nvd
CVE-2022-20361P3CRITICALCVSS 9.8v10.0v11.0+3 more2022-08-10
CVE-2022-20361 [CRITICAL] CWE-269 CVE-2022-20361: In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Der In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-
nvd
Google Android vulnerabilities | cvebase