Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 148 of 339
CVE-2021-25330P4HIGHCVSS 7.5v10.02021-03-02
CVE-2021-25330 [HIGH] CVE-2021-25330: Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows un
Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.
nvd
CVE-2020-25050P4HIGHCVSS 7.5v9.0v10.02020-08-31
CVE-2020-25050 [HIGH] CVE-2020-25050: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The CMC service
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The CMC service allows attackers to obtain sensitive information. The Samsung ID is SVE-2020-17288 (August 2020).
nvd
CVE-2020-11605P4HIGHCVSS 7.5v8.0v8.1+2 more2020-04-08
CVE-2020-11605 [HIGH] CWE-532 CVE-2020-11605: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There i
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is SVE-2019-16359 (April 2020).
nvd
CVE-2017-18651P4HIGHCVSS 7.5v6.0v6.0.1+4 more2020-04-07
CVE-2017-18651 [HIGH] CWE-190 CVE-2017-18651: An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is an Integ
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is an Integer Overflow in process_M_SetTokenTUIPasswd during handling of a trusted application, leading to memory corruption. The Samsung IDs are SVE-2017-9008 and SVE-2017-9009 (October 2017).
nvd
CVE-2018-21060P4HIGHCVSS 7.5v7.0v7.1.0+4 more2020-04-08
CVE-2018-21060 [HIGH] CWE-200 CVE-2018-21060: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is a Keyboa
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is a Keyboard learned words leak in the locked state via the emergency contact picker. The Samsung IDs are SVE-2018-11989, SVE-2018-11990 (September 2018).
nvd
CVE-2018-21079P4HIGHCVSS 7.5v5.0v5.0.1+10 more2020-04-08
CVE-2018-21079 [HIGH] CWE-401 CVE-2018-21079: An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), N(7.x), and O(8.0) software.
An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), N(7.x), and O(8.0) software. There is a kernel pointer leak in the USB gadget driver. The Samsung ID is SVE-2017-10993 (March 2018).
nvd
CVE-2017-18662P4HIGHCVSS 7.5v6.0v7.0+3 more2020-04-07
CVE-2017-18662 [HIGH] CWE-119 CVE-2017-18662: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Data outside of t
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Data outside of the rkp log buffer boundary is read, causing an information leak. The Samsung ID is SVE-2017-9109 (July 2017).
nvd
CVE-2017-0846P4HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-0846 [HIGH] CWE-200 CVE-2017-0846: An information disclosure vulnerability in the Android framework (clipboardservice). Product: Androi
An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64934810.
nvd
CVE-2017-13152P4HIGHCVSS 7.5v5.1.1v6.0+5 more2017-12-06
CVE-2017-13152 [HIGH] CWE-200 CVE-2017-13152: An information disclosure vulnerability in the Android media framework (libmedia drm). Product: Andr
An information disclosure vulnerability in the Android media framework (libmedia drm). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-62872384.
nvd
CVE-2016-11042P4HIGHCVSS 7.5v5.0v5.1+1 more2020-04-07
CVE-2016-11042 [HIGH] CWE-287 CVE-2016-11042: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SI
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (June 2016).
nvd
CVE-2016-2473P4CRITICALCVSS 9.8≤ 6.0.12016-06-13
CVE-2016-2473 [CRITICAL] CVE-2016-2473: The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501.
nvd
CVE-2017-18676P4HIGHCVSS 7.5v7.02020-04-07
CVE-2017-18676 [HIGH] CWE-20 CVE-2017-18676: An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm chipsets) software. There is
An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm chipsets) software. There is an RKP kernel protection bypass (in which unwanted memory mappings may occur) because of a lack of MSR trapping. The Samsung ID is SVE-2016-7901 (April 2017).
nvd
CVE-2018-21078P4HIGHCVSS 7.5v6.0v7.0+4 more2020-04-08
CVE-2018-21078 [HIGH] CWE-20 CVE-2018-21078: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Cont
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate video calls because SS (Supplementary Service) and USSD (Unstructured Supplementary Service Data) codes are improperly secured. The Samsung ID is SVE-2018-11469 (April 2018).
nvd
CVE-2016-11046P4HIGHCVSS 7.5v4.3v4.4+2 more2020-04-07
CVE-2016-11046 [HIGH] CWE-20 CVE-2016-11046: An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. B
An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages. The Samsung ID is SVE-2016-5733 (May 2016).
nvd
CVE-2017-18666P4HIGHCVSS 7.5v4.4v5.0+6 more2020-04-07
CVE-2017-18666 [HIGH] CWE-862 CVE-2017-18666: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) softw
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Applications can send arbitrary premium SMS messages. The Samsung ID is SVE-2017-8701 (June 2017).
nvd
CVE-2017-18669P4HIGHCVSS 7.5v7.0v7.1.0+2 more2020-04-07
CVE-2017-18669 [HIGH] CWE-276 CVE-2017-18669: An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected A
An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017).
nvd
CVE-2019-20620P4HIGHCVSS 7.5v9.02020-03-24
CVE-2019-20620 [HIGH] CWE-287 CVE-2019-20620: An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application all
An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are SVE-2019-13814, SVE-2019-13815 (March 2019).
nvd
CVE-2017-18683P4CRITICALCVSS 9.8v5.0v5.1+1 more2020-04-07
CVE-2017-18683 [CRITICAL] CWE-20 CVE-2017-18683: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows Hare Hunting during application installation. The Samsung ID is SVE-2016-6942 (February 2017).
nvd
CVE-2017-18684P4CRITICALCVSS 9.8v5.0v5.1+1 more2020-04-07
CVE-2017-18684 [CRITICAL] CWE-20 CVE-2017-18684: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows provider seizure via an application that uses a custom provider. The Samsung ID is SVE-2016-6942 (February 2017).
nvd
CVE-2019-20582P4CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20582 [CRITICAL] CWE-416 CVE-2019-20582: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos9810 chipset
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos9810 chipsets) software. There is a use after free in the ion driver. The Samsung ID is SVE-2019-14837 (August 2019).
nvd