Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 145 of 339
CVE-2014-9879P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9879 [HIGH] CWE-264 CVE-2014-9879: The mdss mdp3 driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does
The mdss mdp3 driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate user-space data, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769221 and Qualcomm internal bug CR524490.
nvd
CVE-2014-9878P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9878 [HIGH] CWE-264 CVE-2014-9878: drivers/mmc/card/mmc_block_test.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5
drivers/mmc/card/mmc_block_test.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not reject kernel-space buffer addresses, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769208 and Qualcomm internal bug CR547479.
nvd
CVE-2015-8943P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2015-8943 [HIGH] CWE-264 CVE-2015-8943: drivers/video/msm/mdss/mdss_mdp_util.c in the Qualcomm components in Android before 2016-08-05 on Ne
drivers/video/msm/mdss/mdss_mdp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not verify that a mapping exists before proceeding with an unmap operation, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28815158 and Qualcomm internal bugs CR794217 and CR836226.
nvd
CVE-2014-9889P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9889 [HIGH] CWE-20 CVE-2014-9889: drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android befor
drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate CPP frame messages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28803645 and Qualcomm internal bug CR674712.
nvd
CVE-2014-9886P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9886 [HIGH] CWE-20 CVE-2014-9886: arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 o
arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate input parameters, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28815575 and Qualcomm internal bug CR555030.
nvd
CVE-2017-0737P4HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-09
CVE-2017-0737 [HIGH] CWE-129 CVE-2017-0737: A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: And
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563942.
nvd
CVE-2017-0805P4HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-24
CVE-2017-0805 [HIGH] CWE-129 CVE-2017-0805: A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: And
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.
nvd
CVE-2016-3747P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-3747 [HIGH] CVE-2016-3747: Use-after-free vulnerability in the mm-video-v4l2 venc component in mediaserver in Android 4.x befor
Use-after-free vulnerability in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27903498.
nvd
CVE-2016-2482P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2482 [HIGH] CWE-119 CVE-2016-2482: The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1
The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27661749.
nvd
CVE-2016-2483P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2483 [HIGH] CWE-119 CVE-2016-2483: The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1
The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27662502.
nvd
CVE-2017-0769P4HIGHCVSS 7.8v7.0v7.1.0+3 more2017-09-08
CVE-2017-0769 [HIGH] CWE-404 CVE-2017-0769: A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: And
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37662122.
nvd
CVE-2017-0767P4HIGHCVSS 7.8v4.0v4.0.1+27 more2017-09-08
CVE-2017-0767 [HIGH] CWE-120 CVE-2017-0767: A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android
A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37536407.
nvd
CVE-2017-0770P4HIGHCVSS 7.8v4.0v4.0.1+28 more2017-09-08
CVE-2017-0770 [HIGH] CVE-2017-0770: A elevation of privilege vulnerability in the Android media framework (libmediaplayerservice). Produ
A elevation of privilege vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38234812.
nvd
CVE-2017-0768P4HIGHCVSS 7.8v4.0v4.0.1+28 more2017-09-08
CVE-2017-0768 [HIGH] CVE-2017-0768: A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android
A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62019992.
nvd
CVE-2017-0684P4HIGHCVSS 7.8v6.0v6.0.1+3 more2017-07-06
CVE-2017-0684 [HIGH] CWE-787 CVE-2017-0684: A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6
A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.
nvd
CVE-2016-2486P4HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2486 [HIGH] CWE-20 CVE-2016-2486: mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2,
mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate the relationship between allocated memory and the frame size, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem
nvd
CVE-2016-2449P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2449 [HIGH] CWE-264 CVE-2016-2449: services/camera/libcameraservice/device3/Camera3Device.cpp in mediaserver in Android 4.x before 4.4.
services/camera/libcameraservice/device3/Camera3Device.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate template IDs, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug
nvd
CVE-2016-2422P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-2422 [HIGH] CWE-264 CVE-2016-2422: Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01
Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate in an unrelated CA role, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26324357.
nvd
CVE-2017-10999P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-10999 [HIGH] CWE-119 CVE-2017-10999: In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls int
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.
nvd
CVE-2017-10997P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-10997 [HIGH] CWE-119 CVE-2017-10997: In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.
nvd