cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 130 of 339
CVE-2020-0183P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0183 [HIGH] CWE-459 CVE-2020-0183: In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-110181479
nvd
CVE-2020-0215P3HIGHCVSS 7.8v8.0v8.1+4 more2020-06-11
CVE-2020-0215 [HIGH] CWE-276 CVE-2020-0215: In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local escalation of privilege that exposes a pairing Bluetooth MAC address with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9 Android-
nvd
CVE-2019-2114P3HIGHCVSS 7.8v8.0v8.1+2 more2019-10-11
CVE-2019-2114 [HIGH] CWE-276 CVE-2019-2114: In the default privileges of NFC, there is a possible local bypass of user interaction requirements In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an application with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android
nvd
CVE-2016-3824P3HIGHCVSS 7.8v4.0v4.0.1+20 more2016-08-05
CVE-2016-3824 [HIGH] CWE-119 CVE-2016-3824: omx/OMXNodeInstance.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5 omx/OMXNodeInstance.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not validate the buffer port, which allows attackers to gain privileges via a crafted application, aka internal bug 28816827.
nvd
CVE-2016-3823P3HIGHCVSS 7.8v4.0v4.0.1+20 more2016-08-05
CVE-2016-3823 [HIGH] CWE-119 CVE-2016-3823: The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted application, aka internal bug 28815329.
nvd
CVE-2020-0118P3HIGHCVSS 7.8v10.0vAndroid-102020-06-10
CVE-2020-0118 [HIGH] CWE-20 CVE-2020-0118: In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150904694
nvd
CVE-2019-2175P3HIGHCVSS 7.8v9.0vAndroid-92019-09-05
CVE-2019-2175 [HIGH] CWE-863 CVE-2019-2175: In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypas In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2020-0051P3HIGHCVSS 7.8v10.0vAndroid-102020-03-10
CVE-2020-0051 [HIGH] CWE-1021 CVE-2020-0051: In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to l In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138442483
nvd
CVE-2019-20592P3HIGHCVSS 7.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20592 [HIGH] CWE-89 CVE-2019-20592: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Story Video Editor Content Provider. The Samsung ID is SVE-2019-14062 (July 2019).
nvd
CVE-2019-20574P3HIGHCVSS 7.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20574 [HIGH] CWE-89 CVE-2019-20574: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content Provider. The Samsung ID is SVE-2019-14061 (August 2019).
nvd
CVE-2017-3748P3HIGHCVSS 7.8≤ 5.1.12017-06-29
CVE-2017-3748 [HIGH] CVE-2017-3748: On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device).
nvd
CVE-2017-11059P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11059 [HIGH] CWE-119 CVE-2017-11059: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.
nvd
CVE-2020-10829P3HIGHCVSS 7.8v8.0v9.0+1 more2020-03-24
CVE-2020-10829 [HIGH] CWE-787 CVE-2020-10829: An issue was discovered on Samsung mobile devices with O(8.0), P(9.0), and Q(10.0) (Broadcom chipset An issue was discovered on Samsung mobile devices with O(8.0), P(9.0), and Q(10.0) (Broadcom chipsets) software. A kernel driver heap overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-15880 (March 2020).
nvd
CVE-2017-0871P3HIGHCVSS 7.8v8.02017-12-06
CVE-2017-0871 [HIGH] CVE-2017-0871: An elevation of privilege vulnerability in the Android framework (framework base). Product: Android. An elevation of privilege vulnerability in the Android framework (framework base). Product: Android. Versions: 8.0. Android ID A-65281159.
nvd
CVE-2017-0837P3HIGHCVSS 7.8v5.1.1v6.0+5 more2017-12-06
CVE-2017-0837 [HIGH] CVE-2017-0837: An elevation of privilege vulnerability in the Android media framework (libaudiopolicymanager). Prod An elevation of privilege vulnerability in the Android media framework (libaudiopolicymanager). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64340921.
nvd
CVE-2017-13153P3HIGHCVSS 7.8v8.02017-12-06
CVE-2017-13153 [HIGH] CWE-665 CVE-2017-13153: An elevation of privilege vulnerability in the Android media framework (libaudioservice). Product: A An elevation of privilege vulnerability in the Android media framework (libaudioservice). Product: Android. Versions: 8.0. Android ID A-65280854.
nvd
CVE-2017-0870P3HIGHCVSS 7.8v5.1.1v6.0+5 more2017-12-06
CVE-2017-0870 [HIGH] CVE-2017-0870: An elevation of privilege vulnerability in the Android framework (libminikin). Product: Android. Ver An elevation of privilege vulnerability in the Android framework (libminikin). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-62134807.
nvd
CVE-2017-9683P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-9683 [HIGH] CWE-190 CVE-2017-9683: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a meta image, an integer overflow can occur, if user-defined image offset and size values are too large.
nvd
CVE-2017-11057P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11057 [HIGH] CWE-119 CVE-2017-11057: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in compatibility mode, flash_data from 64-bit userspace may cause disclosure of kernel memory or a fault due to using a userspace-provided address.
nvd
CVE-2019-20773P3HIGHCVSS 7.8v7.0v7.1+4 more2020-04-17
CVE-2019-20773 [HIGH] CVE-2019-20773: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 softwa An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).
nvd
Google Android vulnerabilities | cvebase