cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 154 of 339
CVE-2017-8251P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-8251 [HIGH] CWE-129 CVE-2017-8251: In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not checked, and could overflow the array stream_cfg_cmd->stream_handle.
nvd
CVE-2016-3922P4HIGHCVSS 7.8v6.0v6.0.1+1 more2016-10-10
CVE-2016-3922 [HIGH] CWE-264 CVE-2016-3922: libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 reli libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 relies on variable-length arrays, which allows attackers to gain privileges via a crafted application, aka internal bug 30202619.
nvd
CVE-2021-25470P4HIGHCVSS 7.9v9.0v10.0+1 more2021-10-06
CVE-2021-25470 [HIGH] CWE-94 CVE-2021-25470: An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
nvd
CVE-2016-3750P4HIGHCVSS 7.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-3750 [HIGH] CWE-20 CVE-2016-3750: libs/binder/Parcel.cpp in the Parcels Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2 libs/binder/Parcel.cpp in the Parcels Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the return value of the dup system call, which allows attackers to bypass an isolation protection mechanism via a crafted application, aka internal bug 28395952.
nvd
CVE-2020-12754P4HIGHCVSS 7.8v7.2v8.0+3 more2020-05-11
CVE-2020-12754 [HIGH] CVE-2020-12754: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A cr An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application can obtain control of device input via the window system service. The LG ID is LVE-SMP-170011 (May 2020).
nvd
CVE-2016-11045P4HIGHCVSS 7.8v5.0v5.12020-04-07
CVE-2016-11045 [HIGH] CWE-119 CVE-2016-11045: An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. The Gallery library allo An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. The Gallery library allow memory corruption via a malformed image. The Samsung ID is SVE-2016-5317 (May 2016).
nvd
CVE-2017-0818P4HIGHCVSS 7.5v6.0v6.0.1+4 more2017-10-04
CVE-2017-0818 [HIGH] CWE-772 CVE-2017-0818: A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63581671.
nvd
CVE-2017-0819P4HIGHCVSS 7.5v6.0v6.0.1+4 more2017-10-04
CVE-2017-0819 [HIGH] CWE-682 CVE-2017-0819: A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63045918.
nvd
CVE-2016-5857P4HIGHCVSS 7.8v7.02017-03-20
CVE-2016-5857 [HIGH] CWE-264 CVE-2016-5857: The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.
nvd
CVE-2016-0810P4HIGHCVSS 7.8v4.0v4.0.1+22 more2016-02-07
CVE-2016-0810 [HIGH] CWE-264 CVE-2016-0810: media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, an media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requirements, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25781119.
nvd
CVE-2019-20542P4HIGHCVSS 7.8v7.1v8.0+2 more2020-03-24
CVE-2019-20542 [HIGH] CWE-787 CVE-2019-20542: An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (Exynos chipsets) software. There is a stack overflow in the kernel driver. The Samsung ID is SVE-2019-15034 (November 2019).
nvd
CVE-2020-10851P4HIGHCVSS 7.8v9.0v10.02020-03-24
CVE-2020-10851 [HIGH] CWE-787 CVE-2020-10851: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack overflow in the kperfmon driver. The Samsung ID is SVE-2019-15876 (January 2020).
nvd
CVE-2020-10852P4HIGHCVSS 7.8v8.0v8.1+2 more2020-03-24
CVE-2020-10852 [HIGH] CWE-787 CVE-2020-10852: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There i An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a stack overflow in display driver. The Samsung ID is SVE-2019-15877 (January 2020).
nvd
CVE-2017-0553P4HIGHCVSS 7.0v5.0v5.0.1+9 more2017-04-07
CVE-2017-0553 [HIGH] CWE-190 CVE-2017-0553: An elevation of privilege vulnerability in libnl could enable a local malicious application to execu An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.
nvd
CVE-2011-3901P4HIGHCVSS 7.5v2.3.72020-02-12
CVE-2011-3901 [HIGH] CWE-200 CVE-2011-3901: Android SQLite Journal before 4.0.1 has an information disclosure vulnerability. Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
nvd
CVE-2016-7989P4HIGHCVSS 7.5v4.2.2v4.3+14 more2016-10-31
CVE-2016-7989 [HIGH] CWE-254 CVE-2016-7989: On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message se On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar. This causes the Android runtime to continually crash, rendering the device unusable until a factory reset is
nvd
CVE-2017-13198P4HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13198 [HIGH] CWE-20 CVE-2017-13198: A vulnerability in the Android media framework (ex) related to composition of frames lacking a color A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68399117.
nvd
CVE-2016-11039P4HIGHCVSS 7.5v4.4v5.0+2 more2020-04-07
CVE-2016-11039 [HIGH] CWE-476 CVE-2016-11039: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (AP + CP MDM9 An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (AP + CP MDM9x35, or Qualcomm Onechip) software. There is a NULL pointer dereference issue in the IPC socket code. The Samsung ID is SVE-2016-5980 (July 2016).
nvd
CVE-2017-13186P4HIGHCVSS 7.5v6.0v6.0.1+5 more2018-01-12
CVE-2017-13186 [HIGH] CWE-20 CVE-2017-13186: A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65735716.
nvd
CVE-2017-18679P4HIGHCVSS 7.5v6.02020-04-07
CVE-2017-18679 [HIGH] CWE-20 CVE-2017-18679: An issue was discovered on Samsung mobile devices with M(6.0) software. SLocation can cause a system An issue was discovered on Samsung mobile devices with M(6.0) software. SLocation can cause a system crash via a call to an API that is not implemented. The Samsung ID is SVE-2017-8285 (April 2017).
nvd
Google Android vulnerabilities | cvebase