Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 160 of 339
CVE-2016-6674P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-6674 [HIGH] CWE-20 CVE-2016-6674: system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via
system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via a crafted application, aka internal bug 30445380.
nvd
CVE-2016-6673P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-6673 [HIGH] CWE-264 CVE-2016-6673: The NVIDIA camera driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to gain pr
The NVIDIA camera driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 30204201.
nvd
CVE-2016-6672P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-6672 [HIGH] CWE-264 CVE-2016-6672: The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 5X devices allows attackers t
The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 30537088.
nvd
CVE-2017-9720P4HIGHCVSS 7.8≤ 8.02017-09-21
CVE-2017-9720 [HIGH] CWE-193 CVE-2017-9720: In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera driver, an out-of-bounds read/write can occur.
nvd
CVE-2016-6695P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-6695 [CRITICAL] CWE-119 CVE-2016-6695: sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted visualizer data length, aka Qualcomm internal bug CR 1033540.
nvd
CVE-2016-4477P4HIGHCVSS 7.8v4.4.4v5.0.2+3 more2016-05-09
CVE-2016-4477 [HIGH] CWE-19 CVE-2016-4477: wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, whic
wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.
nvd
CVE-2016-2504P4HIGHCVSS 7.8≤ 6.0.12016-08-05
CVE-2016-2504 [HIGH] CWE-264 CVE-2016-2504: The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices all
The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28026365 and Qualcomm internal bug CR1002974.
nvd
CVE-2014-9868P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9868 [HIGH] CWE-264 CVE-2014-9868: drivers/media/platform/msm/camera_v2/sensor/csiphy/msm_csiphy.c in the Qualcomm components in Androi
drivers/media/platform/msm/camera_v2/sensor/csiphy/msm_csiphy.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via an application that provides a crafted mask value, aka Android internal bug 28749721 and Qualcomm internal bug CR511976.
nvd
CVE-2017-0813P4HIGHCVSS 7.5v7.0v7.1.0+2 more2017-10-04
CVE-2017-0813 [HIGH] CWE-772 CVE-2017-0813: A denial of service vulnerability in the Android media framework (libstagefright). Product: Android.
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36531046.
nvd
CVE-2019-20538P4HIGHCVSS 7.8v9.02020-03-24
CVE-2019-20538 [HIGH] CWE-787 CVE-2019-20538: An issue was discovered on Samsung mobile devices with P(9.0) software. There is a heap overflow in
An issue was discovered on Samsung mobile devices with P(9.0) software. There is a heap overflow in the knox_kap driver. The Samsung ID is SVE-2019-14857 (November 2019).
nvd
CVE-2016-11044P4HIGHCVSS 7.8v5.0v5.1+1 more2020-04-07
CVE-2016-11044 [HIGH] CWE-347 CVE-2016-11044: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint suppo
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).
nvd
CVE-2016-7988P4HIGHCVSS 7.5v4.2.2v4.3+14 more2016-10-31
CVE-2016-7988 [HIGH] CWE-275 CVE-2016-7988: On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible
On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the com.[Samsung].android.intent.action.SET_WIFI intent leads to unsolicited configuration messages being handled by wifi-service.jar within the Android Framework, a subset of SVE-2016-6542.
nvd
CVE-2017-0858P4HIGHCVSS 7.5v6.0v6.0.1+4 more2017-11-16
CVE-2017-0858 [HIGH] CWE-20 CVE-2017-0858: Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1,
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.
nvd
CVE-2017-0857P4HIGHCVSS 7.5v6.0v6.0.1+4 more2017-11-16
CVE-2017-0857 [HIGH] CWE-369 CVE-2017-0857: Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1,
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65122447.
nvd
CVE-2020-35553P4HIGHCVSS 7.5v10.0v11.02020-12-18
CVE-2020-35553 [HIGH] CWE-920 CVE-2020-35553: An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They allows attackers to cause a denial of service (unlock failure) by triggering a power-shortage incident that causes a false-positive attack detection. The Samsung ID is SVE-2020-19678 (December 2020).
nvd
CVE-2020-13830P4HIGHCVSS 7.5v9.02020-06-04
CVE-2020-13830 [HIGH] CWE-532 CVE-2020-13830: An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak
An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).
nvd
CVE-2017-13254P4HIGHCVSS 7.5v6.0v6.0.1+5 more2018-04-04
CVE-2017-13254 [HIGH] CVE-2017-13254: A other vulnerability in the Android media framework (AACExtractor). Product: Android. Versions: 6.0
A other vulnerability in the Android media framework (AACExtractor). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70239507.
nvd
CVE-2017-18682P4HIGHCVSS 7.5v4.4v5.0+3 more2020-04-07
CVE-2017-18682 [HIGH] CWE-755 CVE-2017-18682: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) softw
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Because of incorrect exception handling and an unprotected intent, AudioService can cause a system crash, The Samsung IDs are SVE-2017-8114, SVE-2017-8116, and SVE-2017-8117 (March 2017).
nvd
CVE-2017-18674P4HIGHCVSS 7.5v7.02020-04-07
CVE-2017-18674 [HIGH] CWE-20 CVE-2017-18674: An issue was discovered on Samsung mobile devices with N(7.0) software. The time service (aka Timase
An issue was discovered on Samsung mobile devices with N(7.0) software. The time service (aka Timaservice) allows a kernel panic. The Samsung ID is SVE-2017-8593 (May 2017).
nvd
CVE-2017-13264P4HIGHCVSS 7.5v6.0v6.0.1+5 more2018-04-04
CVE-2017-13264 [HIGH] CVE-2017-13264: A other vulnerability in the Android media framework (Avcdec). Product: Android. Versions: 6.0, 6.0.
A other vulnerability in the Android media framework (Avcdec). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70294343.
nvd