Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 163 of 339
CVE-2020-0279P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0279 [MEDIUM] CWE-125 CVE-2020-0279: In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could
In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-131430997
nvd
CVE-2025-36938P4MEDIUMCVSS 6.8vAndroid kernel2025-12-11
CVE-2025-36938 [MEDIUM] CWE-693 CVE-2025-36938: In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the cod
In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0021P4MEDIUMCVSS 6.5v10.0vAndroid-102020-02-13
CVE-2020-0021 [MEDIUM] CWE-476 CVE-2020-0021: In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-se
In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. This could lead to remote denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141413692
nvd
CVE-2026-0119P4MEDIUMCVSS 6.8vAndroid kernel2026-03-10
CVE-2026-0119 [MEDIUM] CWE-787 CVE-2026-0119: In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memo
In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0335P4MEDIUMCVSS 6.5v11.0vAndroid-112021-02-10
CVE-2021-0335 [MEDIUM] CWE-416 CVE-2021-0335: In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. Th
In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160346309
nvd
CVE-2020-0355P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0355 [MEDIUM] CWE-125 CVE-2020-0355: In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check. This coul
In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141883493
nvd
CVE-2020-0492P4MEDIUMCVSS 6.5v11.0vAndroid-112020-12-15
CVE-2020-0492 [MEDIUM] CWE-125 CVE-2020-0492: In BitstreamFillCache of bitstream.cpp, there is a possible out of bounds read due to a heap buffer
In BitstreamFillCache of bitstream.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154058264
nvd
CVE-2020-0494P4MEDIUMCVSS 6.5v11.0vAndroid-112020-12-15
CVE-2020-0494 [MEDIUM] CWE-125 CVE-2020-0494: In ih264d_parse_ave of ih264d_sei.c, there is a possible out of bounds read due to a heap buffer ove
In ih264d_parse_ave of ih264d_sei.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-152895390
nvd
CVE-2020-0270P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0270 [MEDIUM] CWE-125 CVE-2020-0270: In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to
In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145790628
nvd
CVE-2020-0324P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0324 [MEDIUM] CWE-125 CVE-2020-0324: In libsonivox, there is a possible out of bounds read due to a missing bounds check. This could lead
In libsonivox, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136660304
nvd
CVE-2020-0364P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0364 [MEDIUM] CWE-125 CVE-2020-0364: In libDRCdec, there is a possible out of bounds read due to a missing bounds check. This could lead
In libDRCdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137282770
nvd
CVE-2020-0127P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0127 [MEDIUM] CWE-125 CVE-2020-0127: In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bo
In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140054506
nvd
CVE-2020-0006P4MEDIUMCVSS 6.5v8.0v8.1+6 more2020-01-08
CVE-2020-0006 [MEDIUM] CWE-908 CVE-2020-0006: In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of he
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, And
nvd
CVE-2020-0193P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0193 [MEDIUM] CWE-125 CVE-2020-0193: In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a poss
In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-1445954
nvd
CVE-2023-21400P4MEDIUMCVSS 6.7vAndroid kernel2023-07-13
CVE-2023-21400 [MEDIUM] CWE-667 CVE-2023-21400: In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper l
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0175P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0175 [MEDIUM] CWE-20 CVE-2020-0175: In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation
In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-126380818
nvd
CVE-2019-2129P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2019-08-20
CVE-2019-2129 [MEDIUM] CWE-125 CVE-2019-2129: In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 And
nvd
CVE-2020-0370P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0370 [MEDIUM] CWE-125 CVE-2020-0370: In libAACdec, there is a possible out of bounds read due to missing bounds check. This could lead to
In libAACdec, there is a possible out of bounds read due to missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-112051700
nvd
CVE-2020-0192P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0192 [MEDIUM] CWE-20 CVE-2020-0192: In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds rea
In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144687080
nvd
CVE-2020-0200P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0200 [MEDIUM] CWE-125 CVE-2020-0200: In ReadLittleEndian of raw_bit_reader.cc, there is a possible out of bounds read due to a missing bo
In ReadLittleEndian of raw_bit_reader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147231862
nvd