Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 157 of 339
CVE-2025-22432P4MEDIUMCVSS 6.7v13.0v14.0+6 more2025-12-08
CVE-2025-22432 [MEDIUM] CWE-20 CVE-2025-22432: In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to
In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9395P4MEDIUMCVSS 6.7vKernel2024-12-04
CVE-2018-9395 [MEDIUM] CWE-787 CVE-2018-9395: In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/me
In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_vendor.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9393P4MEDIUMCVSS 6.7vKernel2024-12-04
CVE-2018-9393 [MEDIUM] CWE-787 CVE-2018-9393: In procfile_write of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_proc.c, there is a pos
In procfile_write of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_proc.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9394P4MEDIUMCVSS 6.7vKernel2024-12-04
CVE-2018-9394 [MEDIUM] CWE-787 CVE-2018-9394: In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is
In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32319P4MEDIUMCVSS 6.7v16.0v162025-12-08
CVE-2025-32319 [MEDIUM] CWE-862 CVE-2025-32319: In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep fore
In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36900P4MEDIUMCVSS 6.7vAndroid kernel2025-09-04
CVE-2025-36900 [MEDIUM] CWE-190 CVE-2025-36900: In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer over
In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20228P4MEDIUMCVSS 6.5v12.0v12.1+1 more2022-07-13
CVE-2022-20228 [MEDIUM] CWE-416 CVE-2022-20228: In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use af
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213850092
nvd
CVE-2017-18695P4MEDIUMCVSS 6.5v4.4v5.0+3 more2020-04-07
CVE-2017-18695 [MEDIUM] CWE-522 CVE-2017-18695: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) softw
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654 (January 2017).
nvd
CVE-2018-9353P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-11-27
CVE-2018-9353 [MEDIUM] CWE-125 CVE-2018-9353: In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read
In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9351P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-11-27
CVE-2018-9351 [MEDIUM] CWE-125 CVE-2018-9351: In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to m
In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9349P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-11-27
CVE-2018-9349 [MEDIUM] CWE-125 CVE-2018-9349: In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This c
In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2017-13313P4MEDIUMCVSS 6.5v6.0v6.0.1+10 more2024-11-15
CVE-2017-13313 [MEDIUM] CWE-835 CVE-2017-13313: In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite l
In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2017-13320P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-11-27
CVE-2017-13320 [MEDIUM] CWE-125 CVE-2017-13320: In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds ch
In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9350P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-11-27
CVE-2018-9350 [MEDIUM] CWE-125 CVE-2018-9350: In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing boun
In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9423P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-12-02
CVE-2018-9423 [MEDIUM] CWE-125 CVE-2018-9423: In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c there is a possible out of bound read du
In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c there is a possible out of bound read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2015-1536P4HIGHCVSS 8.5≤ 5.12015-10-01
CVE-2015-1536 [HIGH] CWE-189 CVE-2015-1536: Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in
Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in Android before 5.1.1 LMY48I allows attackers to cause a denial of service (system_server crash) or obtain sensitive system_server memory-content information via a crafted application that leverages improper unmarshalling of bitmaps, aka internal bug 196669
nvd
CVE-2016-2468P4HIGHCVSS 7.8≤ 6.0.12016-06-13
CVE-2016-2468 [HIGH] CVE-2016-2468: The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows att
The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privileges via a crafted application, aka internal bug 27475454.
nvd
CVE-2016-2469P4HIGHCVSS 7.8≤ 6.0.12016-06-13
CVE-2016-2469 [HIGH] CVE-2016-2469: The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attacker
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27531992.
nvd
CVE-2016-3857P4HIGHCVSS 7.8≤ 6.0.12016-08-05
CVE-2016-3857 [HIGH] CWE-264 CVE-2016-3857: The kernel in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privilege
The kernel in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 28522518.
nvd
CVE-2016-3865P4HIGHCVSS 7.8≤ 7.02016-09-11
CVE-2016-3865 [HIGH] CWE-264 CVE-2016-3865: The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attac
The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.
nvd