cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 150 of 339
CVE-2024-32899P4HIGHCVSS 7.0vAndroid kernel2024-06-13
CVE-2024-32899 [HIGH] CWE-362 CVE-2024-32899: In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected mem In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9461P4HIGHCVSS 7.0v6.0v6.0.1+6 more2025-01-18
CVE-2018-9461 [HIGH] CWE-362 CVE-2018-9461: In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23716P4HIGHCVSS 7.0vAndroid SoC2024-09-11
CVE-2024-23716 [HIGH] CWE-416 CVE-2024-23716: In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race conditi In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49724P4HIGHCVSS 7.0v12.0v12.1+8 more2025-01-21
CVE-2024-49724 [HIGH] CWE-276 CVE-2024-49724: In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions a In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-20801P4HIGHCVSS 7.0v13.0v14.0+2 more2026-01-06
CVE-2025-20801 [HIGH] CWE-415 CVE-2025-20801: In seninf, there is a possible memory corruption due to a race condition. This could lead to local e In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10251210; Issue ID: MSV-4926.
nvd
CVE-2021-0312P4MEDIUMCVSS 6.5v8.0v8.1+8 more2021-01-11
CVE-2021-0312 [MEDIUM] CWE-190 CVE-2021-0312: In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer ov In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-
nvd
CVE-2021-0311P4MEDIUMCVSS 6.5v8.0v8.1+8 more2021-01-11
CVE-2021-0311 [MEDIUM] CWE-787 CVE-2021-0311: In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0,
nvd
CVE-2017-0854P4CRITICALCVSS 9.1v6.0v6.0.1+4 more2017-11-16
CVE-2017-0854 [CRITICAL] CWE-125 CVE-2017-0854: An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Vers An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63873837.
nvd
CVE-2017-0853P4CRITICALCVSS 9.1v6.0v6.0.1+4 more2017-11-16
CVE-2017-0853 [CRITICAL] CVE-2017-0853: An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Vers An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63121644.
nvd
CVE-2017-13150P4CRITICALCVSS 9.1v6.0v6.0.1+4 more2017-12-06
CVE-2017-13150 [CRITICAL] CWE-200 CVE-2017-13150: An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Vers An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-38328132.
nvd
CVE-2017-13149P4CRITICALCVSS 9.1v5.1.1v6.0+5 more2017-12-06
CVE-2017-13149 [CRITICAL] CWE-200 CVE-2017-13149: An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Vers An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65719872.
nvd
CVE-2021-0964P4MEDIUMCVSS 6.5v9.0v10.0+3 more2021-12-15
CVE-2021-0964 [MEDIUM] CWE-681 CVE-2021-0964: In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap b In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-193363621
nvd
CVE-2026-0086P4MEDIUMCVSS 6.8v16.0-qpr2_beta_1v16.0-qpr2_beta_2+2 more2026-06-01
CVE-2026-0086 [MEDIUM] CWE-269 CVE-2026-0086: In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0690P3MEDIUMCVSS 6.5v8.1v9.0+3 more2021-10-06
CVE-2021-0690 [MEDIUM] CWE-787 CVE-2021-0690: In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-182
nvd
CVE-2024-39436P4MEDIUMCVSS 6.7v13.0v14.02024-10-09
CVE-2024-39436 [MEDIUM] CWE-77 CVE-2024-39436: In linkturbonative service, there is a possible command injection due to improper input validation. In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2024-39438P4MEDIUMCVSS 6.7v13.0v14.02024-10-09
CVE-2024-39438 [MEDIUM] CWE-77 CVE-2024-39438: In linkturbonative service, there is a possible command injection due to improper input validation. In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2024-39437P4MEDIUMCVSS 6.7v13.0v14.02024-10-09
CVE-2024-39437 [MEDIUM] CWE-77 CVE-2024-39437: In linkturbonative service, there is a possible command injection due to improper input validation. In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2021-39667P4MEDIUMCVSS 6.5v10.0v11.0+2 more2022-03-16
CVE-2021-39667 [MEDIUM] CWE-787 CVE-2021-39667: In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-205702093
nvd
CVE-2021-0971P4MEDIUMCVSS 6.5v9.0v10.0+3 more2021-12-15
CVE-2021-0971 [MEDIUM] CWE-787 CVE-2021-0971: In MPEG4Source::read of MPEG4Extractor.cpp, there is a possible out of bounds write due to a missing In MPEG4Source::read of MPEG4Extractor.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-188893559
nvd
CVE-2025-36902P4MEDIUMCVSS 6.7vAndroid kernel2025-09-04
CVE-2025-36902 [MEDIUM] CWE-122 CVE-2025-36902: In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase