Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 151 of 339
CVE-2024-56187P4MEDIUMCVSS 6.6vAndroid kernel2025-03-10
CVE-2024-56187 [MEDIUM] CWE-125 CVE-2024-56187: In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to
In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9352P3MEDIUMCVSS 6.5v7.1v7.1.1+5 more2024-11-27
CVE-2018-9352 [MEDIUM] CWE-190 CVE-2018-9352: In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integ
In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9348P3MEDIUMCVSS 6.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9348 [MEDIUM] CWE-190 CVE-2018-9348: In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote
In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-25427P4MEDIUMCVSS 6.5v8.1v9.0+2 more2021-07-08
CVE-2021-25427 [MEDIUM] CWE-89 CVE-2021-25427: SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information
nvd
CVE-2016-2434P4HIGHCVSS 7.8≤ 6.0.12016-05-09
CVE-2016-2434 [HIGH] CWE-264 CVE-2016-2434: The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27251090.
nvd
CVE-2017-0381P4HIGHCVSS 7.8v5.0v5.0.1+8 more2017-01-12
CVE-2017-0381 [HIGH] CWE-190 CVE-2017-0381: An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could ena
An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Androi
nvd
CVE-2016-3867P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3867 [HIGH] CWE-264 CVE-2016-3867: The Qualcomm IPA driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to
The Qualcomm IPA driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28919863 and Qualcomm internal bug CR1037897.
nvd
CVE-2016-6676P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-6676 [HIGH] CWE-119 CVE-2016-6676: Off-by-one error in CORE/HDD/src/wlan_hdd_cfg.c in the Qualcomm Wi-Fi driver in Android before 2016-
Off-by-one error in CORE/HDD/src/wlan_hdd_cfg.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application that makes a GET_CFG ioctl call, aka Android internal bug 30874066 and Qualcomm internal bug CR 1000853.
nvd
CVE-2016-6675P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-6675 [HIGH] CWE-119 CVE-2016-6675: Off-by-one error in CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2
Off-by-one error in CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application that makes a linkspeed ioctl call, aka Android internal bug 30873776 and Qualcomm internal bug CR 10
nvd
CVE-2016-3873P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3873 [HIGH] CWE-264 CVE-2016-3873: The NVIDIA kernel in Android before 2016-09-05 on Nexus 9 devices allows attackers to gain privilege
The NVIDIA kernel in Android before 2016-09-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 29518457.
nvd
CVE-2016-3868P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3868 [HIGH] CWE-264 CVE-2016-3868: The Qualcomm power driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers t
The Qualcomm power driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28967028 and Qualcomm internal bug CR1032875.
nvd
CVE-2016-3869P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3869 [HIGH] CWE-264 CVE-2016-3869: The Broadcom Wi-Fi driver in Android before 2016-09-05 on Nexus 5, Nexus 6, Nexus 6P, Nexus 9, Nexus
The Broadcom Wi-Fi driver in Android before 2016-09-05 on Nexus 5, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29009982 and Broadcom internal bug RB#96070.
nvd
CVE-2014-9784P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9784 [HIGH] CWE-119 CVE-2014-9784: Multiple buffer overflows in drivers/char/diag/diag_debugfs.c in the Qualcomm components in Android
Multiple buffer overflows in drivers/char/diag/diag_debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28442449 and Qualcomm internal bug CR585147.
nvd
CVE-2014-9788P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9788 [HIGH] CWE-119 CVE-2014-9788: Multiple buffer overflows in the voice drivers in the Qualcomm components in Android before 2016-07-
Multiple buffer overflows in the voice drivers in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28573112 and Qualcomm internal bug CR548872.
nvd
CVE-2014-9780P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9780 [HIGH] CWE-264 CVE-2014-9780: drivers/video/msm/mdss/mdp3_ctrl.c in the Qualcomm components in Android before 2016-07-05 on Nexus
drivers/video/msm/mdss/mdp3_ctrl.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5, 5X, and 6P devices does not validate start and length values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28602014 and Qualcomm internal bug CR542222.
nvd
CVE-2014-9779P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9779 [HIGH] CWE-264 CVE-2014-9779: arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm components in Android before 2016-07-05 on
arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to obtain sensitive information from kernel memory via a crafted offset, aka Android internal bug 28598347 and Qualcomm internal bug CR548679.
nvd
CVE-2014-9787P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9787 [HIGH] CWE-189 CVE-2014-9787: Integer overflow in drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 o
Integer overflow in drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28571496 and Qualcomm internal bug CR545764.
nvd
CVE-2014-9785P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9785 [HIGH] CWE-264 CVE-2014-9785: drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) dev
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices does not validate addresses before copying data, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28469042 and Qualcomm internal bug CR545747.
nvd
CVE-2014-9871P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9871 [HIGH] CWE-119 CVE-2014-9871: Multiple buffer overflows in drivers/media/platform/msm/camera_v2/isp/msm_isp_util.c in the Qualcomm
Multiple buffer overflows in drivers/media/platform/msm/camera_v2/isp/msm_isp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28749803 and Qualcomm internal bug CR514717.
nvd
CVE-2014-9802P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2014-9802 [HIGH] CWE-264 CVE-2014-9802: Multiple integer overflows in lib/libfdt/fdt.c in the Qualcomm components in Android before 2016-07-
Multiple integer overflows in lib/libfdt/fdt.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28821965 and Qualcomm internal bug CR705108.
nvd