cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 142 of 339
CVE-2017-0879P4CRITICALCVSS 9.1v5.1.1v6.0+5 more2017-12-06
CVE-2017-0879 [CRITICAL] CWE-200 CVE-2017-0879: An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Vers An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65025028.
nvd
CVE-2017-13187P4CRITICALCVSS 9.1v5.1.1v6.0+6 more2018-01-12
CVE-2017-13187 [CRITICAL] CWE-200 CVE-2017-13187: An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65034175.
nvd
CVE-2017-13185P4CRITICALCVSS 9.1v5.1.1v6.0+5 more2018-01-12
CVE-2017-13185 [CRITICAL] CWE-200 CVE-2017-13185: An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65123471.
nvd
CVE-2020-11604P4CRITICALCVSS 9.1v9.0v10.02020-04-08
CVE-2020-11604 [CRITICAL] CWE-125 CVE-2020-11604: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) so An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. There is an Out-of-bounds read in the MLDAP Trustlet. The Samsung ID is SVE-2019-16565 (April 2020).
nvd
CVE-2018-21081P4CRITICALCVSS 9.1v7.0v7.1.0+2 more2020-04-08
CVE-2018-21081 [CRITICAL] CWE-732 CVE-2018-21081: An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the secon An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the runtime permissions of the first app without a user's consent. The Samsung ID is SVE-2017-11018 (March 2018).
nvd
CVE-2026-0128P3MEDIUMCVSS 6.5vAndroid kernel2026-06-16
CVE-2026-0128 [MEDIUM] CWE-190 CVE-2026-0128: In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overfl In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-0092P4MEDIUMCVSS 6.5v12.0v12.1+8 more2025-08-26
CVE-2025-0092 [MEDIUM] CWE-345 CVE-2025-0092: In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misle In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2016-5696P4MEDIUMCVSS 4.8≤ 7.02016-08-06
CVE-2016-5696 [MEDIUM] CWE-200 CVE-2016-5696: net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challeng net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
nvd
CVE-2017-9725P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-9725 [HIGH] CWE-682 CVE-2017-9725: In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocatio In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
nvd
CVE-2018-21085P4HIGHCVSS 8.1v5.0v5.0.1+9 more2020-04-08
CVE-2018-21085 [HIGH] CWE-362 CVE-2018-21085: An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant use-after-free in vnswap_deinit_backing_storage. The Samsung ID is SVE-2017-11176 (February 2018).
nvd
CVE-2018-21086P4HIGHCVSS 8.1v5.0v5.0.1+9 more2020-04-08
CVE-2018-21086 [HIGH] CWE-362 CVE-2018-21086: An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant double free in vnswap_init_backing_storage. The Samsung ID is SVE-2017-11177 (February 2018).
nvd
CVE-2018-21084P4HIGHCVSS 8.1v5.1v6.0+4 more2020-04-08
CVE-2018-21084 [HIGH] CWE-362 CVE-2018-21084: An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition with a resultant read-after-free issue in get_kek. The Samsung ID is SVE-2017-11174 (February 2018).
nvd
CVE-2018-21040P4HIGHCVSS 8.1v8.0v8.1+1 more2020-04-08
CVE-2018-21040 [HIGH] CWE-362 CVE-2018-21040: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) soft An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant use-after-free in the g2d driver. The Samsung ID is SVE-2018-12959 (December 2018).
nvd
CVE-2019-20568P4HIGHCVSS 8.1v8.0v8.1+1 more2020-03-24
CVE-2019-20568 [HIGH] CWE-362 CVE-2019-20568: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos and Qualcom An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos and Qualcomm chipsets) software. A race condition causes a Use-After-Free. The Samsung ID is SVE-2019-15067 (September 2019).
nvd
CVE-2017-0554P4HIGHCVSS 7.8v4.0v4.0.1+26 more2017-04-07
CVE-2017-0554 [HIGH] CWE-862 CVE-2017-0554: An elevation of privilege vulnerability in the Telephony component could enable a local malicious ap An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions
nvd
CVE-2015-6640P4HIGHCVSS 7.8v4.4.4v5.0+2 more2016-01-06
CVE-2015-6640 [HIGH] CWE-264 CVE-2015-6640: The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2 The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
nvd
CVE-2014-9789P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9789 [HIGH] CWE-264 CVE-2014-9789: The (1) alloc and (2) free APIs in arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm compone The (1) alloc and (2) free APIs in arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices do not validate parameters, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28749392 and Qualcomm internal bug CR556425.
nvd
CVE-2015-6647P4HIGHCVSS 7.8v5.0v5.0.1+4 more2016-01-06
CVE-2015-6647 [HIGH] CWE-264 CVE-2015-6647: The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.
nvd
CVE-2015-6637P4HIGHCVSS 7.8v4.4.4v5.0+3 more2016-01-06
CVE-2015-6637 [HIGH] CWE-264 CVE-2015-6637: The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attacker The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.
nvd
CVE-2014-9781P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9781 [HIGH] CWE-119 CVE-2014-9781: Buffer overflow in drivers/video/fbcmap.c in the Qualcomm components in Android before 2016-07-05 on Buffer overflow in drivers/video/fbcmap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28410333 and Qualcomm internal bug CR556471.
nvd
Google Android vulnerabilities | cvebase