Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 138 of 339
CVE-2020-28341P4HIGHCVSS 7.8v10.02020-11-08
CVE-2020-28341 [HIGH] CWE-120 CVE-2020-28341: An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID is SVE-2020-18632 (November 2020).
nvd
CVE-2018-9524P4HIGHCVSS 7.8v7.0v7.1.1+3 more2018-11-14
CVE-2018-9524 [HIGH] CWE-1021 CVE-2018-9524: In functionality implemented in System UI, there are insufficient protections implemented around ove
In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Andro
nvd
CVE-2013-6770P4HIGHCVSS 7.6v4.42014-03-31
CVE-2013-6770 [HIGH] CWE-264 CVE-2013-6770: The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not proper
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows attackers to gain privileges by leveraging ADB shell access and a certain Linux UID, and then creating a Trojan horse script.
nvd
CVE-2019-2089P4HIGHCVSS 7.8v10.0vAndroid-102020-03-15
CVE-2019-2089 [HIGH] CWE-732 CVE-2019-2089: In app uninstallation, there is a possible set of permissions that may not be removed from a shared
In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10 Android ID: A-116608833
nvd
CVE-2020-0015P4HIGHCVSS 7.8v8.0v8.1+3 more2020-02-13
CVE-2020-0015 [HIGH] CVE-2020-0015: In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation d
In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-1390
nvd
CVE-2017-11056P4HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11056 [HIGH] CWE-119 CVE-2017-11056: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while doing sha and cipher operations, a userspace buffer is directly accessed in kernel space potentially leading to a page fault.
nvd
CVE-2017-11067P4HIGHCVSS 7.8v8.02017-10-10
CVE-2017-11067 [HIGH] CWE-119 CVE-2017-11067: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not have a proper address sanity check which may potentially lead to the use of an out-of-range pointer offset.
nvd
CVE-2017-13154P3HIGHCVSS 7.8v5.1.1v6.0+5 more2017-12-06
CVE-2017-13154 [HIGH] CWE-416 CVE-2017-13154: An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: An
An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63666573.
nvd
CVE-2017-0838P3HIGHCVSS 7.8v7.0v7.1.1+1 more2017-11-16
CVE-2017-0838 [HIGH] CVE-2017-0838: An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: An
An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-63522818.
nvd
CVE-2020-10842P4HIGHCVSS 7.8v8.0v8.1+2 more2020-03-24
CVE-2020-10842 [HIGH] CWE-787 CVE-2020-10842: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets)
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There is a heap out-of-bounds write in the tsmux driver. The Samsung ID is SVE-2019-16295 (February 2020).
nvd
CVE-2019-20541P3HIGHCVSS 7.8v9.02020-03-24
CVE-2019-20541 [HIGH] CWE-787 CVE-2019-20541: An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi
An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have a stack overflow. The Samsung IDs are SVE-2019-14965, SVE-2019-14966, SVE-2019-14968, SVE-2019-14969, SVE-2019-14970, SVE-2019-14980, SVE-2019-14981, SVE-2019-14982, SVE-2019-14983, SVE-2019-14984, SVE-2019-15122, SVE-2019-15123 (Nove
nvd
CVE-2020-35554P4HIGHCVSS 7.8v8.0v8.1+2 more2020-12-18
CVE-2020-35554 [HIGH] CVE-2020-35554: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There i
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL error-handler vulnerability. The LG ID is LVE-SMP-200026 (December 2020).
nvd
CVE-2022-30726P4HIGHCVSS 7.8v12.02022-06-07
CVE-2022-30726 [HIGH] CWE-20 CVE-2022-30726: Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SM
Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.
nvd
CVE-2016-3831P4HIGHCVSS 7.5v4.0v4.0.1+20 more2016-08-05
CVE-2016-3831 [HIGH] CWE-20 CVE-2016-3831: The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ time value of 2038-01-19 or later that is mishandled by the system clock, aka internal bug 29083635, related to a "Year 2038 problem."
nvd
CVE-2016-3753P4HIGHCVSS 7.5v4.0v4.0.1+14 more2016-07-11
CVE-2016-3753 [HIGH] CWE-200 CVE-2016-3753: mediaserver in Android 4.x before 4.4.4 allows remote attackers to obtain sensitive information via
mediaserver in Android 4.x before 4.4.4 allows remote attackers to obtain sensitive information via unspecified vectors, aka internal bug 27210135.
nvd
CVE-2017-0389P4HIGHCVSS 7.5v6.0v6.0.1+2 more2017-01-12
CVE-2017-0389 [HIGH] CWE-20 CVE-2017-0389: A denial of service vulnerability in core networking could enable a remote attacker to use specially
A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31850211.
nvd
CVE-2017-13243P4HIGHCVSS 7.5v5.1.1v6.0+5 more2018-02-12
CVE-2017-13243 [HIGH] CWE-200 CVE-2017-13243: A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1
A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991.
nvd
CVE-2015-3854P4HIGHCVSS 7.5v5.0v5.0.1+4 more2016-08-07
CVE-2015-3854 [HIGH] CWE-284 CVE-2015-3854: packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allow
packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.
nvd
CVE-2017-11062P4HIGHCVSS 7.5v8.02017-10-10
CVE-2017-11062 [HIGH] CWE-125 CVE-2017-11062: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently attributes are not validated in __wlan_hdd_cfg80211_do_acs which can potentially lead to a buffer overread.
nvd
CVE-2020-26602P4HIGHCVSS 7.5v8.1v9.0+2 more2020-10-06
CVE-2020-26602 [HIGH] CWE-668 CVE-2020-26602: An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), a
An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (October 2020).
nvd