Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 132 of 339
CVE-2020-13836P3HIGHCVSS 7.5v8.0v8.1+2 more2020-06-04
CVE-2020-13836 [HIGH] CWE-22 CVE-2020-13836: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResP
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).
nvd
CVE-2016-7991P3HIGHCVSS 7.5v4.2.2v4.3+14 more2016-10-31
CVE-2016-7991 [HIGH] CWE-388 CVE-2016-7991: On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in th
On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.
nvd
CVE-2016-3926P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-3926 [CRITICAL] CVE-2016-3926: Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5, 5X, 6, an
Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5, 5X, 6, and 6P devices has unknown impact and attack vectors, aka internal bug 28823953.
nvd
CVE-2020-25065P3HIGHCVSS 7.5v4.4v5.0+8 more2020-08-31
CVE-2020-25065 [HIGH] CWE-203 CVE-2020-25065: An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1,
An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August 2020).
nvd
CVE-2015-9547P3HIGHCVSS 7.5v4.3v4.4.22020-04-10
CVE-2015-9547 [HIGH] CWE-200 CVE-2015-9547: An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of the log file if the error message is "Unhandled exception in Dalvik VM," "Application not responding ANR event," or "Crash on an application's native code."
nvd
CVE-2021-25480P3HIGHCVSS 7.5v8.0v8.1+3 more2021-10-06
CVE-2021-25480 [HIGH] CWE-294 CVE-2021-25480: A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem pr
A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.
nvd
CVE-2018-21041P3HIGHCVSS 7.5v8.0v8.12020-04-08
CVE-2018-21041 [HIGH] CWE-306 CVE-2018-21041: An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Sec
An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The Samsung ID is SVE-2018-13057 (December 2018).
nvd
CVE-2020-28344P3HIGHCVSS 7.5v8.0v8.1+2 more2020-11-08
CVE-2020-28344 [HIGH] CWE-476 CVE-2020-28344: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200024 (November 2020).
nvd
CVE-2018-21069P3HIGHCVSS 7.5v7.0v7.1.0+2 more2020-04-08
CVE-2018-21069 [HIGH] CWE-200 CVE-2018-21069: An issue was discovered on Samsung mobile devices with N(7.x) (MediaTek chipsets) software. There is
An issue was discovered on Samsung mobile devices with N(7.x) (MediaTek chipsets) software. There is information disclosure (of kernel stack memory) in a MediaTek driver. The Samsung ID is SVE-2018-11852 (July 2018).
nvd
CVE-2018-21039P3HIGHCVSS 7.5v7.02020-04-08
CVE-2018-21039 [HIGH] CWE-863 CVE-2018-21039: An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission
An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypass the lockscreen. The Samsung ID is SVE-2018-12053 (December 2018).
nvd
CVE-2019-9424P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9424 [HIGH] CWE-200 CVE-2019-9424: In the Screen Lock, there is a possible information disclosure due to an unusual root cause. In cert
In the Screen Lock, there is a possible information disclosure due to an unusual root cause. In certain circumstances, the setting to hide the unlock pattern can be ignored. Product: AndroidVersions: Android-10Android ID: A-110941092
nvd
CVE-2021-25471P3HIGHCVSS 7.5v8.1v9.0+1 more2021-10-06
CVE-2021-25471 [HIGH] CWE-20 CVE-2021-25471: A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.
nvd
CVE-2016-11029P3HIGHCVSS 7.5v5.0v5.1+2 more2020-04-07
CVE-2016-11029 [HIGH] CWE-522 CVE-2016-11029: An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Atta
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-2016-7301 (December 2016).
nvd
CVE-2016-3927P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-3927 [CRITICAL] CVE-2016-3927: Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P de
Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823244.
nvd
CVE-2016-3929P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-3929 [CRITICAL] CVE-2016-3929: Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P de
Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823675.
nvd
CVE-2020-25051P3HIGHCVSS 7.5v9.0v10.02020-08-31
CVE-2020-25051 [HIGH] CVE-2020-25051: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can by
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppInfo. The Samsung ID is SVE-2020-17758 (August 2020).
nvd
CVE-2020-15579P3HIGHCVSS 7.5v8.0v8.1+2 more2020-07-07
CVE-2020-15579 [HIGH] CVE-2020-15579: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attacke
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via the KNOX API. The Samsung ID is SVE-2020-17318 (July 2020).
nvd
CVE-2019-20565P3HIGHCVSS 7.5v8.0v8.1+1 more2020-03-24
CVE-2019-20565 [HIGH] CWE-287 CVE-2019-20565: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can cha
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication. The Samsung ID is SVE-2018-13300 (September 2019).
nvd
CVE-2018-21047P3HIGHCVSS 7.5v8.0v8.12020-04-08
CVE-2018-21047 [HIGH] CWE-862 CVE-2018-21047: An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Pro
An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins before the Setup Wizard finishes. The Samsung ID is SVE-2018-12894 (November 2018).
nvd
CVE-2020-13834P3HIGHCVSS 7.5v8.0v8.1+2 more2020-06-04
CVE-2020-13834 [HIGH] CWE-863 CVE-2020-13834: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) so
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict use of Android Debug Bridge (adb) for arbitrary installations. The Samsung ID is SVE-2020-17369 (June 2020).
nvd