Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 15 of 339
CVE-2021-0930P3HIGHCVSS 8.8v9.0v10.0+3 more2021-12-15
CVE-2021-0930 [HIGH] CWE-787 CVE-2021-0930: In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to
In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-18
nvd
CVE-2018-9466P3HIGHCVSS 8.8v7.0v7.1.1+7 more2024-11-19
CVE-2018-9466 [HIGH] CWE-787 CVE-2018-9466: In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This
In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9380P3HIGHCVSS 8.8v7.0v7.1.1+5 more2024-12-02
CVE-2018-9380 [HIGH] CWE-787 CVE-2018-9380: In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to improper input val
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-40129P3HIGHCVSS 8.8v12.0v12.1+4 more2023-10-27
CVE-2023-40129 [HIGH] CWE-787 CVE-2023-40129: In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22411P3HIGHCVSS 8.8v15.0v152025-08-26
CVE-2025-22411 [HIGH] CWE-416 CVE-2025-22411: In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic e
In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22412P3HIGHCVSS 8.8v15.0v152025-08-26
CVE-2025-22412 [HIGH] CWE-416 CVE-2025-22412: In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in t
In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-3832P3CRITICALCVSS 10.0≤ 5.12015-10-01
CVE-2015-3832 [CRITICAL] CWE-119 CVE-2015-3832: Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I all
Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via invalid size values of NAL units in MP4 data, aka internal bug 19641538.
nvd
CVE-2016-0815P3CRITICALCVSS 9.8v4.0v4.0.1+22 more2016-03-12
CVE-2016-0815 [CRITICAL] CWE-20 CVE-2016-0815: The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26365349.
nvdosv
CVE-2026-0122P3HIGHCVSS 8.4vAndroid kernel2026-03-10
CVE-2026-0122 [HIGH] CWE-787 CVE-2026-0122: In multiple places, there is a possible out of bounds write due to memory corruption. This could lea
In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-0803P3CRITICALCVSS 9.8v4.0v4.0.1+23 more2016-02-07
CVE-2016-0803 [CRITICAL] CWE-119 CVE-2016-0803: libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2
libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation in the (1) SoftMPEG4Encoder or (2) SoftVPXEncoder component, aka internal bug
nvd
CVE-2016-7990P3CRITICALCVSS 9.8v4.2.2v4.3+14 more2016-10-31
CVE-2016-7990 [CRITICAL] CWE-190 CVE-2016-7990: On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so whe
On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.
nvd
CVE-2016-2428P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2428 [CRITICAL] CWE-119 CVE-2016-2428: libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x b
libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly limit the number of threads, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted media file, aka internal bug 26751339.
nvd
CVE-2016-3819P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-08-05
CVE-2016-3819 [CRITICAL] CWE-119 CVE-2016-3819: Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Andr
Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28533562.
nvd
CVE-2020-12746P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-05-11
CVE-2020-12746 [CRITICAL] CWE-787 CVE-2020-12746: An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets)
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets) software. Attackers can bypass the Secure Bootloader protection mechanism via a heap-based buffer overflow to execute arbitrary code. The Samsung ID is SVE-2020-16712 (May 2020).
nvd
CVE-2019-2007P3CRITICALCVSS 9.8v8.1v9.0+1 more2019-06-19
CVE-2019-2007 [CRITICAL] CWE-190 CVE-2019-2007: In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID
nvd
CVE-2019-2111P3CRITICALCVSS 9.8v9.0vAndroid-92019-07-08
CVE-2019-2111 [CRITICAL] CWE-416 CVE-2019-2111: In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. Thi
In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122856181.
nvd
CVE-2021-25360P3CRITICALCVSS 9.8v10.02021-04-09
CVE-2021-25360 [CRITICAL] CWE-122 CVE-2021-25360: An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
nvd
CVE-2021-25384P3CRITICALCVSS 9.8v8.1v9.0+2 more2021-06-11
CVE-2021-25384 [CRITICAL] CWE-122 CVE-2021-25384: An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in li
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
nvd
CVE-2022-20532P3CRITICALCVSS 9.8v13.0vAndroid-132023-03-24
CVE-2022-20532 [CRITICAL] CWE-190 CVE-2022-20532: In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an i
In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-232242894
nvd
CVE-2023-48424P3CRITICALCVSS 9.8vAndroid SoC2023-12-11
CVE-2023-48424 [CRITICAL] CVE-2023-48424: U-Boot shell vulnerability resulting in Privilege escalation in a production device
U-Boot shell vulnerability resulting in Privilege escalation in a production device
nvd