cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 136 of 339
CVE-2016-3887P4HIGHCVSS 7.8v7.02016-09-11
CVE-2016-3887 [HIGH] CWE-264 CVE-2016-3887: providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce the DISALLOW_CONFIG_VPN setting, which allows attackers to bypass an intended always-on VPN state via a crafted application, aka internal bug 29899712.
nvd
CVE-2016-3833P4HIGHCVSS 7.8v5.0v5.0.1+4 more2016-08-05
CVE-2016-3833 [HIGH] CWE-264 CVE-2016-3833: The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 doe The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka internal bug 29189712.
nvd
CVE-2016-2412P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-2412 [HIGH] CWE-264 CVE-2016-2412: include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x bef include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01, mishandles certain crashes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26593930.
nvd
CVE-2017-0667P4HIGHCVSS 7.8v5.0.2v5.1.1+5 more2017-07-06
CVE-2017-0667 [HIGH] CWE-20 CVE-2017-0667: A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37478824.
nvd
CVE-2017-0664P4HIGHCVSS 7.8v5.0.2v5.1.1+5 more2017-07-06
CVE-2017-0664 [HIGH] CVE-2017-0664: A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36491278.
nvd
CVE-2017-0665P4HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-07-06
CVE-2017-0665 [HIGH] CWE-20 CVE-2017-0665: A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36991414.
nvd
CVE-2017-0831P4HIGHCVSS 7.8v8.02017-11-16
CVE-2017-0831 [HIGH] CWE-732 CVE-2017-0831: An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Android ID: A-37442941.
nvd
CVE-2017-0666P4HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-07-06
CVE-2017-0666 [HIGH] CWE-682 CVE-2017-0666: A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.
nvd
CVE-2017-10998P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-10998 [HIGH] CWE-119 CVE-2017-10998: In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_loo In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is fully within the valid region. If the buffer length is large enough then the address + length operation could overflow and produce a result far below the
nvd
CVE-2017-0752P4HIGHCVSS 7.8v4.0v4.0.1+27 more2017-09-08
CVE-2017-0752 [HIGH] CWE-732 CVE-2017-0752: A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. V A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
nvd
CVE-2017-0830P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-11-16
CVE-2017-0830 [HIGH] CWE-732 CVE-2017-0830: An elevation of privilege vulnerability in the Android framework (device policy client). Product: An An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62623498.
nvd
CVE-2016-3914P4HIGHCVSS 7.8v4.0v4.0.1+21 more2016-10-10
CVE-2016-3914 [HIGH] CWE-362 CVE-2016-3914: Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0 Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that modifies a database between two open operations, aka internal bug 30481342.
nvd
CVE-2016-2485P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2485 [HIGH] CWE-119 CVE-2016-2485: libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, a libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes for the GSM and G711 codecs, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27793367.
nvd
CVE-2016-2484P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2484 [HIGH] CWE-119 CVE-2016-2484: libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, a libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes for the GSM and G711 codecs, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27793163.
nvd
CVE-2016-2480P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2480 [HIGH] CWE-20 CVE-2016-2480: The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1 The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate certain OMX parameter data structures, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27
nvd
CVE-2016-2450P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2450 [HIGH] CWE-264 CVE-2016-2450: codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0. codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 275
nvd
CVE-2016-2451P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2451 [HIGH] CWE-264 CVE-2016-2451: codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x befor codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate VPX output buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 275
nvd
CVE-2017-0800P4HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0800 [HIGH] CVE-2017-0800: A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android ker A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.
nvd
CVE-2017-0799P4HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0799 [HIGH] CVE-2017-0799: A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.
nvd
CVE-2017-0798P4HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0798 [HIGH] CVE-2017-0798: A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android k A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36100671. References: M-ALPS03365532.
nvd
Google Android vulnerabilities | cvebase