cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 149 of 339
CVE-2018-21058P4CRITICALCVSS 9.8v7.0v8.02020-04-08
CVE-2018-21058 [CRITICAL] CWE-327 CVE-2018-21058: An issue was discovered on Samsung mobile devices with N(7.0), O(8.0) (exynos7420 or Exynos 8890/899 An issue was discovered on Samsung mobile devices with N(7.0), O(8.0) (exynos7420 or Exynos 8890/8996 chipsets) software. Cache attacks can occur against the Keymaster AES-GCM implementation because T-Tables are used; the Cryptography Extension (CE) is not used. The Samsung ID is SVE-2018-12761 (September 2018).
nvd
CVE-2016-3841P4HIGHCVSS 7.3v6.0.12016-08-06
CVE-2016-3841 [HIGH] CWE-264 CVE-2016-3841: The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
nvd
CVE-2018-9587P4HIGHCVSS 7.3v7.0v7.1.1+4 more2019-02-11
CVE-2018-9587 [HIGH] CWE-552 CVE-2018-9587: In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, And In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a confused deputy scenario. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction
nvd
CVE-2019-2200P4HIGHCVSS 7.3v10.0vAndroid-102020-02-13
CVE-2019-2200 [HIGH] CWE-276 CVE-2019-2200: In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obt In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-6731
nvd
CVE-2019-2043P4HIGHCVSS 7.3v7.0v7.1.1+5 more2019-05-08
CVE-2019-2043 [HIGH] CWE-1188 CVE-2019-2043: In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege du In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android Versions
nvd
CVE-2019-9309P4HIGHCVSS 7.3v10.0vAndroid-102019-09-27
CVE-2019-9309 [HIGH] CWE-787 CVE-2019-9309: In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117985575
nvd
CVE-2019-9463P4HIGHCVSS 7.3v10.0vAndroid-102019-09-27
CVE-2019-9463 [HIGH] CVE-2019-9463: In Platform, there is a possible bypass of user interaction requirements due to background app inter In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113584607
nvd
CVE-2020-0271P4HIGHCVSS 7.3v11.0vAndroid-112020-09-18
CVE-2020-0271 [HIGH] CWE-1188 CVE-2020-0271: In the Settings app, there is an insecure default value. This could lead to local escalation of priv In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144507081
nvd
CVE-2019-9269P4HIGHCVSS 7.3v10.0vAndroid-102019-09-27
CVE-2019-9269 [HIGH] CWE-613 CVE-2019-9269: In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36899497
nvd
CVE-2019-2125P4HIGHCVSS 7.3v7.0v7.1.1+5 more2019-08-20
CVE-2019-2125 [HIGH] CWE-1021 CVE-2019-2125: In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay att In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Andr
nvd
CVE-2022-20442P3HIGHCVSS 7.3v10.0v11.0+2 more2022-12-13
CVE-2022-20442 [HIGH] CWE-1021 CVE-2022-20442: In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a se In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Andro
nvd
CVE-2026-0132P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0132 CVE-2026-0132: In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0044P3MEDIUMCVSS 6.7v12.0v12.1+7 more2024-03-11
CVE-2024-0044 [MEDIUM] CWE-74 CVE-2024-0044: In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2013-3666P4HIGHCVSS 7.2v4.1.22013-05-29
CVE-2013-3666 [HIGH] CWE-264 CVE-2013-3666: The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attack The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB Debugging mode, using Android Debug Bridge (adb) to establish a USB connection, dialing 3845#*973#, modifying the WLAN Test Wi-Fi Ping Test/User Command tcpdump command string, and pressing the CANCEL butt
nvd
CVE-2015-6621P4CRITICALCVSS 9.3v5.0v5.1+1 more2015-12-08
CVE-2015-6621 [CRITICAL] CWE-264 CVE-2015-6621: SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privi SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23909438.
nvd
CVE-2024-32920P4HIGHCVSS 7.1vAndroid kernel2024-06-13
CVE-2024-32920 [HIGH] CWE-125 CVE-2024-32920: In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds c In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34731P4HIGHCVSS 7.0v12.0v12.1+6 more2024-08-15
CVE-2024-34731 [HIGH] CWE-362 CVE-2024-34731: In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0041P4HIGHCVSS 7.0v14.0v142024-02-16
CVE-2024-0041 [HIGH] CWE-362 CVE-2024-0041: In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32891P4HIGHCVSS 7.0vAndroid kernel2024-06-13
CVE-2024-32891 [HIGH] CWE-362 CVE-2024-32891: In sec_media_unprotect of media.c, there is a possible memory corruption due to a race condition. Th In sec_media_unprotect of media.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31327P4HIGHCVSS 7.0v12.0v12.1+6 more2024-07-09
CVE-2024-31327 [HIGH] CWE-362 CVE-2024-31327: In multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race c In multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase