cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 14 of 339
CVE-2020-0086P3CRITICALCVSS 9.8v10.0vAndroid-102020-03-15
CVE-2020-0086 [CRITICAL] CWE-190 CVE-2020-0086: In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. Th In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arbitrary code execution if IntSan were not enabled, which it is by default. No additional execution privileges are required. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-1318593
nvd
CVE-2023-20946P3CRITICALCVSS 9.8v11.0v12.0+3 more2023-02-28
CVE-2023-20946 [CRITICAL] CVE-2023-20946: In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-1
nvd
CVE-2023-6181P3CRITICALCVSS 9.8vAndroid SoC2023-12-11
CVE-2023-6181 [CRITICAL] CVE-2023-6181: An oversight in BCB handling of reboot reason that allows for persistent code execution An oversight in BCB handling of reboot reason that allows for persistent code execution
nvd
CVE-2023-48417P3CRITICALCVSS 9.8vAndroid SoC2023-12-11
CVE-2023-48417 [CRITICAL] CWE-862 CVE-2023-48417: Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Appl Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
nvd
CVE-2024-44097P3CRITICALCVSS 9.8vunknown2024-10-02
CVE-2024-44097 [CRITICAL] CWE-269 CVE-2024-44097: According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malici
nvd
CVE-2016-1621P3CRITICALCVSS 9.8v4.0v4.0.1+22 more2016-03-12
CVE-2016-1621 [CRITICAL] CWE-119 CVE-2016-1621: libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-0 libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
nvd
CVE-2020-0240P3HIGHCVSS 8.8v10.0vAndroid-102020-08-11
CVE-2020-0240 [HIGH] CWE-190 CVE-2020-0240: In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer over In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594
nvd
CVE-2020-0451P3HIGHCVSS 8.8v8.0v8.1+4 more2020-11-10
CVE-2020-0451 [HIGH] CWE-787 CVE-2020-0451: In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds wri In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9 Android-8.0 Android-8.1Android
nvd
CVE-2021-0326P3HIGHCVSS 7.5v8.1v9.0+3 more2021-02-10
CVE-2021-0326 [HIGH] CWE-787 CVE-2021-0326: In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds ch In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android
nvd
CVE-2024-23717P3HIGHCVSS 8.8v12.0v12.1+6 more2024-03-11
CVE-2024-23717 [HIGH] CWE-20 CVE-2024-23717: In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34722P3HIGHCVSS 8.8v12.0v12.1+6 more2024-07-09
CVE-2024-34722 [HIGH] CWE-303 CVE-2024-34722: In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43770P3HIGHCVSS 8.8v12.0v12.1+8 more2025-01-21
CVE-2024-43770 [HIGH] CWE-94 CVE-2024-43770: In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing b In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43771P3HIGHCVSS 8.8v12.0v12.1+8 more2025-01-21
CVE-2024-43771 [HIGH] CWE-94 CVE-2024-43771: In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bo In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43096P3HIGHCVSS 8.8v12.0v12.1+8 more2025-01-21
CVE-2024-43096 [HIGH] CWE-787 CVE-2024-43096: In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing boun In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-12753P3CRITICALCVSS 9.8v7.2v8.0+3 more2020-05-11
CVE-2020-12753 [CRITICAL] CWE-787 CVE-2020-12753: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbi An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May 2020).
nvd
CVE-2019-9459P3CRITICALCVSS 9.8v10.0vAndroid-102019-09-27
CVE-2019-9459 [CRITICAL] CWE-787 CVE-2019-9459: In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remot In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79593569
nvd
CVE-2019-2030P3CRITICALCVSS 9.8v9.02019-04-19
CVE-2019-2030 [CRITICAL] CWE-416 CVE-2019-2030: In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could l In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-119496789.
nvd
CVE-2018-9578P3CRITICALCVSS 9.8v9.02018-12-07
CVE-2018-9578 [CRITICAL] CWE-787 CVE-2018-9578: In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113261928.
nvd
CVE-2017-0782P3HIGHCVSS 8.8v4.0v4.0.1+28 more2017-09-14
CVE-2017-0782 [HIGH] CWE-120 CVE-2017-0782: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146237.
nvd
CVE-2021-0507P3HIGHCVSS 8.8v8.1v9.0+3 more2021-06-21
CVE-2021-0507 [HIGH] CWE-787 CVE-2021-0507: In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bou In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181860042
nvd
Google Android vulnerabilities | cvebase