Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 161 of 339
CVE-2017-13299P4HIGHCVSS 7.5v6.0v6.0.1+5 more2018-04-04
CVE-2017-13299 [HIGH] CVE-2017-13299: A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.
A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.
nvd
CVE-2017-0859P4HIGHCVSS 7.5v6.0v6.0.1+3 more2017-11-16
CVE-2017-0859 [HIGH] CVE-2017-0859: Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1,
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36075131.
nvd
CVE-2020-25063P4HIGHCVSS 7.5v7.2v8.0+3 more2020-08-31
CVE-2020-25063 [HIGH] CWE-20 CVE-2020-25063: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An a
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect application-level input validation. The LG ID is LVE-SMP-200018 (July 2020).
nvd
CVE-2017-18671P4HIGHCVSS 7.5v5.0v5.1+5 more2020-04-07
CVE-2017-18671 [HIGH] CWE-755 CVE-2017-18671: An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Inte
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Intents related to Wi-Fi have incorrect exception handling, leading to a crash of system processes. The Samsung ID is SVE-2017-8389 (May 2017).
nvd
CVE-2017-18670P4HIGHCVSS 7.5v4.4v5.0+2 more2020-04-07
CVE-2017-18670 [HIGH] CWE-755 CVE-2017-18670: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. and
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. android.intent.action.SIOP_LEVEL_CHANGED allows a serializable intent reboot. The Samsung ID is SVE-2017-8363 (May 2017).
nvd
CVE-2019-20612P4HIGHCVSS 7.5v7.0v7.1.0+4 more2020-03-24
CVE-2019-20612 [HIGH] CVE-2019-20612: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Broadcom Wi-Fi, and SEC Wi
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Broadcom Wi-Fi, and SEC Wi-Fi chipsets) software. Wi-Fi allows a denial of service via TCP SYN packets. The Samsung ID is SVE-2018-13162 (March 2019).
nvd
CVE-2019-20619P4HIGHCVSS 7.5v9.02020-03-24
CVE-2019-20619 [HIGH] CVE-2019-20619: An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Startup leaks keyboar
An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Startup leaks keyboard suggested words. The Samsung ID is SVE-2019-13773 (March 2019).
nvd
CVE-2020-13829P4HIGHCVSS 7.5v9.0v10.02020-06-04
CVE-2020-13829 [HIGH] CVE-2020-13829: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can di
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid protection mechanism in the RKP. The Samsung ID is SVE-2019-15998 (June 2020).
nvd
CVE-2016-11043P4HIGHCVSS 7.5v6.02020-04-07
CVE-2016-11043 [HIGH] CWE-326 CVE-2016-11043: An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in
An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).
nvd
CVE-2019-20536P4CRITICALCVSS 9.8v7.1v8.0+3 more2020-03-24
CVE-2019-20536 [CRITICAL] CWE-276 CVE-2019-20536: An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).
nvd
CVE-2017-0445P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0445 [HIGH] CVE-2017-0445: An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32769717.
nvd
CVE-2016-3850P4HIGHCVSS 7.3≤ 6.0.12016-08-05
CVE-2016-3850 [HIGH] CWE-264 CVE-2016-3850: Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nex
Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted header field in a boot image, aka Android internal bug 27917291 and Qualcomm internal bug CR945164.
nvd
CVE-2017-0434P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0434 [HIGH] CVE-2017-0434: An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local mal
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33001936.
nvd
CVE-2017-0446P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0446 [HIGH] CVE-2017-0446: An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32917445.
nvd
CVE-2017-0447P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0447 [HIGH] CVE-2017-0447: An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32919560.
nvd
CVE-2017-6249P4HIGHCVSS 7.0≤ 7.1.22017-07-13
CVE-2017-6249 [HIGH] CVE-2017-6249: An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious ap
An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34373711. References: N-CVE-2017-6249.
nvd
CVE-2017-6248P4HIGHCVSS 7.0v7.1.22017-07-06
CVE-2017-6248 [HIGH] CVE-2017-6248: An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious ap
An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34372667. References: N-CVE-2017-6248.
nvd
CVE-2017-0523P4HIGHCVSS 7.0≤ 7.1.12017-03-08
CVE-2017-0523 [HIGH] CVE-2017-0523: An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-32835279. References: QC-CR#1096945.
nvd
CVE-2017-0620P4HIGHCVSS 7.0≤ 7.1.22017-05-12
CVE-2017-0620 [HIGH] CWE-20 CVE-2017-0620: An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a
An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35401052.
nvd
CVE-2019-2095P4HIGHCVSS 7.0v9.02019-06-07
CVE-2019-2095 [HIGH] CWE-362 CVE-2019-2095: In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after f
In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-124232283.
nvd