cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 164 of 339
CVE-2020-0180P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0180 [MEDIUM] CWE-125 CVE-2020-0180: In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a possible out of bounds read due to a missing In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142861738
nvd
CVE-2020-0205P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0205 [MEDIUM] CWE-125 CVE-2020-0205: In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147234020
nvd
CVE-2020-0207P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0207 [MEDIUM] CWE-20 CVE-2020-0207: In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validatio In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-135532289
nvd
CVE-2020-0211P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0211 [MEDIUM] CWE-125 CVE-2020-0211: In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a mi In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147491773
nvd
CVE-2020-0353P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0353 [MEDIUM] CWE-20 CVE-2020-0353: In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This coul In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777526
nvd
CVE-2020-0362P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0362 [MEDIUM] CWE-20 CVE-2020-0362: In libstagefright, there is a possible resource exhaustion due to improper input validation. This co In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123237930
nvd
CVE-2024-20081P4MEDIUMCVSS 6.7v13.0v14.02024-07-01
CVE-2024-20081 [MEDIUM] CWE-787 CVE-2024-20081: In gnss service, there is a possible out of bounds write due to improper input validation. This coul In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.
nvd
CVE-2021-0368P4MEDIUMCVSS 6.5v11.0vAndroid-112021-03-10
CVE-2021-0368 [MEDIUM] CWE-125 CVE-2021-0368: In oggpack_look of bitwise.c, there is a possible out of bounds read due to a missing bounds check. In oggpack_look of bitwise.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169829774
nvd
CVE-2020-0490P4MEDIUMCVSS 6.5v11.0vAndroid-112020-12-15
CVE-2020-0490 [MEDIUM] CWE-125 CVE-2020-0490: In floor1_info_unpack of floor1.c, there is a possible out of bounds read due to a missing bounds ch In floor1_info_unpack of floor1.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155560008
nvd
CVE-2024-20079P4MEDIUMCVSS 6.7v13.0v14.02024-07-01
CVE-2024-20079 [MEDIUM] CWE-787 CVE-2024-20079: In gnss service, there is a possible out of bounds write due to improper input validation. This coul In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: MSV-1491.
nvd
CVE-2021-0559P4MEDIUMCVSS 6.5v11.0vAndroid-112021-06-22
CVE-2021-0559 [MEDIUM] CWE-125 CVE-2021-0559: In Lag_max of p_ol_wgh.cpp, there is a possible out of bounds read due to a missing bounds check. Th In Lag_max of p_ol_wgh.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172312730
nvd
CVE-2021-0976P4MEDIUMCVSS 6.5v12.0vAndroid-122021-12-15
CVE-2021-0976 [MEDIUM] CWE-125 CVE-2021-0976: In toBARK of floor0.c, there is a possible out of bounds read due to a missing bounds check. This co In toBARK of floor0.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-199680600
nvd
CVE-2020-0320P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0320 [MEDIUM] CWE-20 CVE-2020-0320: In libstagefright, there is a possible resource exhaustion due to improper input validation. This co In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129282427
nvd
CVE-2020-0301P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0301 [MEDIUM] CWE-20 CVE-2020-0301: In libstagefright, there is a possible resource exhaustion due to improper input validation. This co In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124940460
nvd
CVE-2020-0363P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0363 [MEDIUM] CWE-20 CVE-2020-0363: In libmedia, there is a possible resource exhaustion due to improper input validation. This could le In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132274514
nvd
CVE-2021-39803P4MEDIUMCVSS 6.5v10.0v11.0+3 more2022-04-12
CVE-2021-39803 [MEDIUM] CWE-416 CVE-2021-39803: In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-193790350
nvd
CVE-2018-9405P4MEDIUMCVSS 6.7vAndroid Kernel2025-01-18
CVE-2018-9405 [MEDIUM] CWE-787 CVE-2018-9405: In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing b In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21310P4MEDIUMCVSS 6.7fixed in 14.0v142023-10-30
CVE-2023-21310 [MEDIUM] CWE-787 CVE-2023-21310: In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21380P4MEDIUMCVSS 6.7fixed in 14.0v142023-10-30
CVE-2023-21380 [MEDIUM] CWE-787 CVE-2023-21380: In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0551P4MEDIUMCVSS 6.5v11.0vAndroid-112021-06-22
CVE-2021-0551 [MEDIUM] CWE-74 CVE-2021-0551: In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a maliciou In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180518039
nvd
Google Android vulnerabilities | cvebase