Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 131 of 339
CVE-2022-27828P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-27828 [HIGH] CWE-20 CVE-2022-27828: Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attack
Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2022-27827P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-27827 [HIGH] CWE-20 CVE-2022-27827: Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows at
Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2016-11047P3HIGHCVSS 7.8v4.2v4.42020-04-07
CVE-2016-11047 [HIGH] CWE-787 CVE-2016-11047: An issue was discovered on Samsung mobile devices with JBP(4.2) and KK(4.4) (Marvell chipsets) softw
An issue was discovered on Samsung mobile devices with JBP(4.2) and KK(4.4) (Marvell chipsets) software. The ACIPC-MSOCKET driver allows local privilege escalation via a stack-based buffer overflow. The Samsung ID is SVE-2016-5393 (April 2016).
nvd
CVE-2020-10832P3HIGHCVSS 7.8v9.02020-03-24
CVE-2020-10832 [HIGH] CWE-125 CVE-2020-10832: An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. Kernel Wi-
An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. Kernel Wi-Fi drivers allow out-of-bounds Read or Write operations (e.g., a buffer overflow). The Samsung IDs are SVE-2019-16125, SVE-2019-16134, SVE-2019-16158, SVE-2019-16159, SVE-2019-16319, SVE-2019-16320, SVE-2019-16337, SVE-2019-16464, SVE-2019-16465, SVE-20
nvd
CVE-2022-27830P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-27830 [HIGH] CWE-20 CVE-2022-27830: Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to
Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2022-27829P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-27829 [HIGH] CWE-20 CVE-2022-27829: Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows
Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2021-1039P3HIGHCVSS 7.8v9.0v10.0+3 more2021-12-15
CVE-2021-1039 [HIGH] CWE-1021 CVE-2021-1039: In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/ov
In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182808318
nvd
CVE-2020-25060P3HIGHCVSS 7.8v7.2v8.0+3 more2020-08-31
CVE-2020-25060 [HIGH] CVE-2020-25060: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Loca
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).
nvd
CVE-2021-0603P3HIGHCVSS 7.8v11.0vAndroid-112021-07-14
CVE-2021-0603 [HIGH] CWE-1021 CVE-2021-0603: In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts with
In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-182809425
nvd
CVE-2021-25512P3HIGHCVSS 7.8v9.0v10.0+1 more2021-12-08
CVE-2021-25512 [HIGH] CWE-20 CVE-2021-25512: An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers t
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.
nvd
CVE-2021-25428P3HIGHCVSS 7.8v8.1v9.0+2 more2021-07-08
CVE-2021-25428 [HIGH] CWE-269 CVE-2021-25428: Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows un
Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.
nvd
CVE-2022-25815P3HIGHCVSS 7.8v10.0v11.02022-03-10
CVE-2022-25815 [HIGH] CWE-276 CVE-2022-25815: PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
nvd
CVE-2022-39882P3HIGHCVSS 7.8v10.0v11.0+1 more2022-11-09
CVE-2022-39882 [HIGH] CWE-787 CVE-2022-39882: Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov
Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2016-0828P3HIGHCVSS 7.5v5.0v5.0.1+6 more2016-03-12
CVE-2016-0828 [HIGH] CWE-200 CVE-2016-0828: The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserv
The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not initialize a certain slot variable, which allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an ATTACH_BUFFE
nvdosv
CVE-2016-0829P3HIGHCVSS 7.5v4.0v4.0.1+22 more2016-03-12
CVE-2016-0829 [HIGH] CWE-200 CVE-2016-0829: The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserv
The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, which allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by
nvdosv
CVE-2016-0811P3HIGHCVSS 7.5v6.0v6.0.12016-02-07
CVE-2016-0811 [HIGH] CWE-200 CVE-2016-0811: Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplaye
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as demonstrated by obtaining Signature or SignatureOrSyste
nvd
CVE-2019-9371P3MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9371 [MEDIUM] CWE-20 CVE-2019-9371: In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead
In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254
nvd
CVE-2017-9715P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-9715 [HIGH] CWE-125 CVE-2017-9715: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a buffer over-read can occur.
nvd
CVE-2017-9717P3HIGHCVSS 7.5v8.02017-10-10
CVE-2017-9717 [HIGH] CWE-125 CVE-2017-9717: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing Netlink attributes, a buffer overread can occur.
nvd
CVE-2020-12752P3HIGHCVSS 7.5v9.0v10.02020-05-11
CVE-2020-12752 [HIGH] CWE-20 CVE-2020-12752: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. A
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020).
nvd