Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 137 of 339
CVE-2017-0801P4HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0801 [HIGH] CVE-2017-0801: A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: An
A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.
nvd
CVE-2017-0755P4HIGHCVSS 7.8v5.0v5.0.1+11 more2017-09-08
CVE-2017-0755 [HIGH] CVE-2017-0755: A elevation of privilege vulnerability in the Android libraries (libminikin). Product: Android. Vers
A elevation of privilege vulnerability in the Android libraries (libminikin). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-32178311.
nvd
CVE-2016-2448P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2448 [HIGH] CWE-264 CVE-2016-2448: media/libmediaplayerservice/nuplayer/NuPlayerStreamListener.cpp in mediaserver in Android 4.x before
media/libmediaplayerservice/nuplayer/NuPlayerStreamListener.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly validate entry data structures, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem ac
nvd
CVE-2017-9724P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-9724 [HIGH] CWE-269 CVE-2017-9724: In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissio
In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, specifically the ION cache maintenance code is writing to a user supplied address.
nvd
CVE-2017-0703P4HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-07-06
CVE-2017-0703 [HIGH] CWE-732 CVE-2017-0703: A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4,
A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33123882.
nvd
CVE-2016-3766P4HIGHCVSS 7.5v4.0v4.0.1+20 more2016-07-11
CVE-2016-3766 [HIGH] CWE-20 CVE-2016-3766: MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2,
MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not check whether memory allocation succeeds, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28471206.
nvd
CVE-2017-11053P4HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11053 [HIGH] CWE-119 CVE-2017-11053: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when qos map set IE of length less than 16 is received in association response or in qos map configure action frame, a buffer overflow can potentially occur in ConvertQosMapsetFrame().
nvd
CVE-2017-11000P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-11000 [HIGH] CWE-119 CVE-2017-11000: In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera ker
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.
nvd
CVE-2017-0802P4HIGHCVSS 7.8≤ 7.1.22017-09-08
CVE-2017-0802 [HIGH] CVE-2017-0802: A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android k
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.
nvd
CVE-2017-0826P4HIGHCVSS 7.8≤ 8.02017-10-04
CVE-2017-0826 [HIGH] CVE-2017-0826: An elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android k
An elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-34949781.
nvd
CVE-2017-0747P4HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0747 [HIGH] CVE-2017-0747: A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Vers
A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821.
nvd
CVE-2017-0742P4HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0742 [HIGH] CVE-2017-0742: A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android ID: A-36074857. References: M-ALPS03275524.
nvd
CVE-2017-0746P4HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0746 [HIGH] CVE-2017-0746: A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Andro
A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.
nvd
CVE-2017-0707P4HIGHCVSS 7.8v7.1.22017-07-06
CVE-2017-0707 [HIGH] CVE-2017-0707: A elevation of privilege vulnerability in the HTC led driver. Product: Android. Versions: Android ke
A elevation of privilege vulnerability in the HTC led driver. Product: Android. Versions: Android kernel. Android ID: A-36088467.
nvd
CVE-2017-0704P4HIGHCVSS 7.8v7.1.1v7.1.22017-07-06
CVE-2017-0704 [HIGH] CVE-2017-0704: A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 7.1.1,
A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-33059280.
nvd
CVE-2017-0710P4HIGHCVSS 7.8v7.1.22017-07-06
CVE-2017-0710 [HIGH] CVE-2017-0710: A elevation of privilege vulnerability in the Upstream Linux tcb. Product: Android. Versions: Androi
A elevation of privilege vulnerability in the Upstream Linux tcb. Product: Android. Versions: Android kernel. Android ID: A-34951864.
nvd
CVE-2021-0635P4HIGHCVSS 7.8v10.0vAndroid SoC2021-10-06
CVE-2021-0635 [HIGH] CVE-2021-0635: When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface sh
When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss of user rights.Product: Androidversion:Android-10Android ID: A-189402477
nvd
CVE-2021-0636P4HIGHCVSS 7.8v10.0vAndroid SoC2021-10-06
CVE-2021-0636 [HIGH] CVE-2021-0636: When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface sh
When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss of user rights.Product: Androidversion: Android-10Android ID: A-189392423
nvd
CVE-2020-28342P4HIGHCVSS 7.8v9.0v10.02020-11-08
CVE-2020-28342 [HIGH] CVE-2020-28342: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software.
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure application allows attackers to bypass authentication for a locked Gallery application via the Reminder application. The Samsung ID is SVE-2020-18689 (November 2020).
nvd
CVE-2016-3825P4HIGHCVSS 7.8v5.0v5.0.1+4 more2016-08-05
CVE-2016-3825 [HIGH] CWE-119 CVE-2016-3825: mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x b
mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allocates an incorrect amount of memory, which allows attackers to gain privileges via a crafted application, aka internal bug 28816964.
nvd