cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 165 of 339
CVE-2025-36908P4MEDIUMCVSS 6.7vAndroid kernel2025-09-04
CVE-2025-36908 [MEDIUM] CWE-787 CVE-2025-36908: In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an inco In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9403P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2018-9403 [MEDIUM] CWE-787 CVE-2018-9403: In the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possibl In the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local escalation of privilege in a privileged process with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9386P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2018-9386 [MEDIUM] CWE-787 CVE-2018-9386: In reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow du In reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9397P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2018-9397 [MEDIUM] CWE-787 CVE-2018-9397: In WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB write due to a missing b In WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9391P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2018-9391 [MEDIUM] CWE-787 CVE-2018-9391: In update_gps_sv and output_vzw_debug of vendor/mediatek/proprietary/hardware/connectivity/gps/g In update_gps_sv and output_vzw_debug of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/gpshal_wor ker.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9400P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2018-9400 [MEDIUM] CWE-787 CVE-2018-9400: In gt1x_debug_write_proc and gt1x_tool_write of drivers/input/touchscreen/mediatek/GT1151/gt1x_g In gt1x_debug_write_proc and gt1x_tool_write of drivers/input/touchscreen/mediatek/GT1151/gt1x_generic.c and gt1x_tools.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9398P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2018-9398 [MEDIUM] CWE-787 CVE-2018-9398: In fm_set_stat of mediatek FM radio driver, there is a possible OOB write due to improper input In fm_set_stat of mediatek FM radio driver, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9392P4MEDIUMCVSS 6.7vKernel2024-12-04
CVE-2018-9392 [MEDIUM] CWE-787 CVE-2018-9392: In get_binary of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/data_coder.c, the In get_binary of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/data_coder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9396P4MEDIUMCVSS 6.7vKernel2024-12-04
CVE-2018-9396 [MEDIUM] CWE-787 CVE-2018-9396: In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possib In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9376P4MEDIUMCVSS 6.7v6.0v6.0.1+8 more2024-12-02
CVE-2018-9376 [MEDIUM] CWE-787 CVE-2018-9376: In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possib In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29783P4MEDIUMCVSS 6.7vAndroid kernel2024-04-05
CVE-2024-29783 [MEDIUM] CWE-125 CVE-2024-29783: In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53836P4MEDIUMCVSS 6.7vAndroid kernel2025-01-03
CVE-2024-53836 [MEDIUM] CWE-787 CVE-2024-53836: In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buf In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13308P4MEDIUMCVSS 6.7vKernel2024-12-05
CVE-2017-13308 [MEDIUM] CWE-120 CVE-2017-13308: In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow i In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20773P4MEDIUMCVSS 6.7v14.0v15.0+1 more2025-12-02
CVE-2025-20773 [MEDIUM] CWE-416 CVE-2025-20773: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4797.
nvd
CVE-2025-20770P4MEDIUMCVSS 6.7v14.0v15.0+1 more2025-12-02
CVE-2025-20770 [MEDIUM] CWE-416 CVE-2025-20770: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4803.
nvd
CVE-2025-20775P4MEDIUMCVSS 6.7v14.0v15.0+1 more2025-12-02
CVE-2025-20775 [MEDIUM] CWE-416 CVE-2025-20775: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4795.
nvd
CVE-2025-20772P4MEDIUMCVSS 6.7v14.0v15.0+1 more2025-12-02
CVE-2025-20772 [MEDIUM] CWE-416 CVE-2025-20772: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4795.
nvd
CVE-2025-20807P4MEDIUMCVSS 6.7v16.02026-01-06
CVE-2025-20807 [MEDIUM] CWE-190 CVE-2025-20807: In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114841; Issue ID: MSV-4451.
nvd
CVE-2026-20443P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-03-02
CVE-2026-20443 [MEDIUM] CWE-416 CVE-2026-20443: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436998; Issue ID: MSV-5722.
nvd
CVE-2026-20444P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-03-02
CVE-2026-20444 [MEDIUM] CWE-787 CVE-2026-20444: In display, there is a possible memory corruption due to a missing bounds check. This could lead to In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436995; Issue ID: MSV-5721.
nvd
Google Android vulnerabilities | cvebase