cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 146 of 339
CVE-2016-3746P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-3746 [HIGH] CVE-2016-3746: Use-after-free vulnerability in the mm-video-v4l2 vdec component in mediaserver in Android 4.x befor Use-after-free vulnerability in the mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27890802.
nvd
CVE-2017-8277P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-8277 [HIGH] CWE-416 CVE-2017-8277: In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_ In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client, if the client registers failed, it would be freed. However the client was not removed from list. Use-after-free would occur when traversing the list next time.
nvd
CVE-2017-0712P4HIGHCVSS 7.8v5.0v5.0.1+10 more2017-08-09
CVE-2017-0712 [HIGH] CWE-20 CVE-2017-0712: A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. V A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928.
nvd
CVE-2017-0729P4HIGHCVSS 7.8v5.0v5.0.1+10 more2017-08-09
CVE-2017-0729 [HIGH] CWE-190 CVE-2017-0729: A elevation of privilege vulnerability in the Android media framework (mediadrmserver). Product: And A elevation of privilege vulnerability in the Android media framework (mediadrmserver). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37710346.
nvd
CVE-2017-0731P4HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-09
CVE-2017-0731 [HIGH] CWE-763 CVE-2017-0731: A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Andr A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.
nvd
CVE-2017-0732P4HIGHCVSS 7.8v6.0v6.0.1+4 more2017-08-09
CVE-2017-0732 [HIGH] CVE-2017-0732: A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: And A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37504237.
nvd
CVE-2017-9677P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-9677 [HIGH] CWE-119 CVE-2017-9677: In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_comp In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If one thread is running, while another thread is setting data, race conditions will happen. If "ddp->params_length" is
nvd
CVE-2016-11052P4HIGHCVSS 7.8v5.0v5.12020-04-07
CVE-2016-11052 [HIGH] CWE-20 CVE-2016-11052: An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so i An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a malformed JPEG file. The Samsung ID is SVE-2015-5110 (January 2016).
nvd
CVE-2017-0727P4HIGHCVSS 7.8v7.0v7.1.0+2 more2017-08-09
CVE-2017-0727 [HIGH] CWE-362 CVE-2017-0727: A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Ve A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.
nvd
CVE-2016-3754P4HIGHCVSS 7.5v4.0v4.0.1+20 more2016-07-11
CVE-2016-3754 [HIGH] CWE-399 CVE-2016-3754: mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016 mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not limit process-memory usage, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28615448.
nvd
CVE-2020-12749P4HIGHCVSS 7.8v9.02020-05-11
CVE-2020-12749 [HIGH] CWE-120 CVE-2020-12749: An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI Wi-Fi drivers have a buffer overflow. The Samsung ID is SVE-2020-16906 (May 2020).
nvd
CVE-2020-13842P4HIGHCVSS 7.8v7.2v8.0+3 more2020-06-05
CVE-2020-13842 [HIGH] CVE-2020-13842: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets) An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).
nvd
CVE-2020-10841P4HIGHCVSS 7.8v9.0v10.02020-03-24
CVE-2020-10841 [HIGH] CVE-2020-10841: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) sof An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is an arbitrary kfree in the vipx and vertex drivers. The Samsung ID is SVE-2019-16294 (February 2020).
nvd
CVE-2014-9901P4HIGHCVSS 7.5≤ 6.0.12016-08-05
CVE-2014-9901 [HIGH] CWE-284 CVE-2014-9901: The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snp The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cause a denial of service (device hang or reboot) via crafted frames, aka Android internal bug 28670333 and Qualcomm internal bug CR548711.
nvd
CVE-2021-23243P4HIGHCVSS 7.8v11.02021-09-27
CVE-2021-23243 [HIGH] CVE-2021-23243: In Oppo's battery application, the third-party SDK provides the function of loading a third-party Pr In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.
nvd
CVE-2017-0394P4HIGHCVSS 7.5v5.0v5.0.1+8 more2017-01-12
CVE-2017-0394 [HIGH] CVE-2017-0394: A denial of service vulnerability in Telephony could enable a remote attacker to cause a device hang A denial of service vulnerability in Telephony could enable a remote attacker to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31752213.
nvd
CVE-2017-0817P4HIGHCVSS 7.5v4.0v4.0.1+28 more2017-10-04
CVE-2017-0817 [HIGH] CWE-200 CVE-2017-0817: An information disclosure vulnerability in the Android media framework (libstagefright). Product: An An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63522430.
nvd
CVE-2016-3756P4HIGHCVSS 7.5v4.0v4.0.1+20 more2016-07-11
CVE-2016-3756 [HIGH] CWE-20 CVE-2016-3756: Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the number of partitions, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28556125.
nvd
CVE-2016-3755P4HIGHCVSS 7.5v6.0v6.0.12016-07-11
CVE-2016-3755 [HIGH] CWE-20 CVE-2016-3755: decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly sele decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly select concealment frames, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28470138.
nvd
CVE-2017-0840P4HIGHCVSS 7.5v5.0.2v5.1.1+6 more2017-11-16
CVE-2017-0840 [HIGH] CWE-200 CVE-2017-0840: An information disclosure vulnerability in the Android media framework (libstagefright). Product: An An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62948670.
nvd
Google Android vulnerabilities | cvebase