cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 140 of 339
CVE-2019-20771P4HIGHCVSS 7.5v7.0v7.1+4 more2020-04-17
CVE-2019-20771 [HIGH] CVE-2019-20771: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 softwa An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService allows unconfirmed configuration changes via a modified OMACP message. The LG ID is LVE-SMP-190006 (August 2019).
nvd
CVE-2017-18677P4HIGHCVSS 7.5v6.0v7.0+3 more2020-04-07
CVE-2017-18677 [HIGH] CWE-862 CVE-2017-18677: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unp An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unprotected Intent, an attacker can reset the configuration of certain applications. The Samsung ID is SVE-2016-7142 (April 2017).
nvd
CVE-2019-20618P4HIGHCVSS 7.5v9.02020-03-24
CVE-2019-20618 [HIGH] CWE-287 CVE-2019-20618: An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allow An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsung ID is SVE-2018-13765 (March 2019).
nvd
CVE-2016-3760P4HIGHCVSS 7.5v5.0v5.0.1+4 more2016-07-11
CVE-2016-3760 [HIGH] CWE-20 CVE-2016-3760: Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during a session of the primary user, aka internal bug 27410683.
nvd
CVE-2017-18689P4HIGHCVSS 7.5v6.0v7.02020-04-07
CVE-2017-18689 [HIGH] CWE-354 CVE-2017-18689: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos5433, Exynos7420, or An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos5433, Exynos7420, or Exynos7870 chipsets) software. An attacker can bypass a ko (aka Kernel Module) signature by modifying the count of kernel modules. The Samsung ID is SVE-2016-7466 (January 2017).
nvd
CVE-2016-5868P4HIGHCVSS 7.0≤ 8.02017-09-25
CVE-2016-5868 [HIGH] CWE-264 CVE-2016-5868: drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote atta drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.
nvd
CVE-2019-20590P4CRITICALCVSS 9.8v8.0v8.12020-03-24
CVE-2019-20590 [CRITICAL] CWE-191 CVE-2019-20590: An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflow in the Secure Storage Trustlet. The Samsung ID is SVE-2019-13952 (July 2019).
nvd
CVE-2020-0028P4MEDIUMCVSS 6.5v9.0vAndroid-92020-02-13
CVE-2020-0028 [MEDIUM] CVE-2020-0028: In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of p In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-122652057
nvd
CVE-2016-2497P4HIGHCVSS 7.3v4.0v4.0.1+20 more2016-08-05
CVE-2016-2497 [HIGH] CWE-119 CVE-2016-2497: services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to increase intent-filter priority via a crafted application, aka internal bug 27450489.
nvd
CVE-2019-9325P3MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9325 [MEDIUM] CWE-125 CVE-2019-9325: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
nvd
CVE-2016-2410P4HIGHCVSS 7.4v6.0v6.0.12016-04-18
CVE-2016-2410 [HIGH] CWE-264 CVE-2016-2410: A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 26291677.
nvd
CVE-2017-13265P4HIGHCVSS 7.3v7.0v7.1.1+3 more2018-04-04
CVE-2017-13265 [HIGH] CVE-2017-13265: A elevation of privilege vulnerability in the Android system (OTA updates). Product: Android. Versio A elevation of privilege vulnerability in the Android system (OTA updates). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-36232423.
nvd
CVE-2017-13263P4HIGHCVSS 7.3v8.0v8.12018-04-04
CVE-2017-13263 [HIGH] CVE-2017-13263: A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 8.0, 8. A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 8.0, 8.1. Android ID: A-69383160.
nvd
CVE-2019-9358P4HIGHCVSS 7.3v10.0vAndroid-102019-09-27
CVE-2019-9358 [HIGH] CWE-787 CVE-2019-9358: In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120156401
nvd
CVE-2020-0133P4HIGHCVSS 7.3v10.0vAndroid-102020-06-11
CVE-2020-0133 [HIGH] CWE-276 CVE-2020-0133: In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device d In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145136060
nvd
CVE-2019-9386P4HIGHCVSS 7.3v10.0vAndroid-102019-09-27
CVE-2019-9386 [HIGH] CWE-787 CVE-2019-9386: In NFC server, there is a possible out of bounds write due to a missing bounds check. This could lea In NFC server, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122361874
nvd
CVE-2019-2041P4HIGHCVSS 7.3v8.1v9.02019-04-19
CVE-2019-2041 [HIGH] CWE-1188 CVE-2019-2041: In the configuration of NFC modules on certain devices, there is a possible failure to distinguish i In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android I
nvd
CVE-2019-2122P4HIGHCVSS 7.3v7.0v7.1.1+5 more2019-08-20
CVE-2019-2122 [HIGH] CWE-264 CVE-2019-2122: In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the default case between the WindowManager and the Settings. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Andro
nvd
CVE-2021-0434P4HIGHCVSS 7.3v9.0v10.0+2 more2021-12-15
CVE-2021-0434 [HIGH] CVE-2021-0434: In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a mali In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitati
nvd
CVE-2019-2216P4HIGHCVSS 7.3v10.0vAndroid-102020-03-15
CVE-2019-2216 [HIGH] CWE-20 CVE-2019-2216: In overlay notifications, there is a possible hidden notification due to improper input validation. In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlaying app, with User execution privileges needed. User interaction is needed for exploitation.Product: Android Versions: Android-10 Android ID: A-38390530
nvd
Google Android vulnerabilities | cvebase