cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 166 of 339
CVE-2025-20787P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-01-06
CVE-2025-20787 [MEDIUM] CWE-416 CVE-2025-20787: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149879; Issue ID: MSV-4658.
nvd
CVE-2025-20785P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-01-06
CVE-2025-20785 [MEDIUM] CWE-416 CVE-2025-20785: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149882; Issue ID: MSV-4677.
nvd
CVE-2025-20786P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-01-06
CVE-2025-20786 [MEDIUM] CWE-415 CVE-2025-20786: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149882; Issue ID: MSV-4673.
nvd
CVE-2025-36922P4MEDIUMCVSS 6.7vAndroid kernel2025-12-11
CVE-2025-36922 [MEDIUM] CWE-416 CVE-2025-36922: In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. Th In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege in the OS Kernel level with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20805P4MEDIUMCVSS 6.7v16.02026-01-06
CVE-2025-20805 [MEDIUM] CWE-416 CVE-2025-20805: In dpe, there is a possible memory corruption due to use after free. This could lead to local escala In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114696; Issue ID: MSV-4480.
nvd
CVE-2025-20806P4MEDIUMCVSS 6.7v16.02026-01-06
CVE-2025-20806 [MEDIUM] CWE-416 CVE-2025-20806: In dpe, there is a possible memory corruption due to use after free. This could lead to local escala In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114835; Issue ID: MSV-4479.
nvd
CVE-2025-20802P4MEDIUMCVSS 6.7v15.02026-01-06
CVE-2025-20802 [MEDIUM] CWE-416 CVE-2025-20802: In geniezone, there is a possible memory corruption due to use after free. This could lead to local In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10238968; Issue ID: MSV-4914.
nvd
CVE-2025-20804P4MEDIUMCVSS 6.7v16.02026-01-06
CVE-2025-20804 [MEDIUM] CWE-416 CVE-2025-20804: In dpe, there is a possible memory corruption due to use after free. This could lead to local escala In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10198951; Issue ID: MSV-4503.
nvd
CVE-2021-0969P4MEDIUMCVSS 6.5v10.0v11.0+1 more2021-12-15
CVE-2021-0969 [MEDIUM] CWE-755 CVE-2021-0969: In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check. This could lead to remote denial of service if a proximal Wi-Fi AP provides invalid information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-19
nvd
CVE-2021-39671P4MEDIUMCVSS 6.5v12.0vAndroid-122022-02-11
CVE-2021-39671 [MEDIUM] CWE-908 CVE-2021-39671: In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to unini In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206718630
nvd
CVE-2022-20346P4MEDIUMCVSS 6.5v10.0v11.0+3 more2022-08-10
CVE-2022-20346 [MEDIUM] CWE-125 CVE-2022-20346: In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAn
nvd
CVE-2021-25483P4MEDIUMCVSS 6.5v8.1v9.0+2 more2021-10-06
CVE-2021-25483 [MEDIUM] CWE-125 CVE-2021-25483: Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 all Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.
nvd
CVE-2018-9429P4MEDIUMCVSS 6.5v8.12024-12-02
CVE-2018-9429 [MEDIUM] CWE-125 CVE-2018-9429: In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitial In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-40076P4MEDIUMCVSS 5.5v14.0v142023-12-04
CVE-2023-40076 [MEDIUM] CWE-276 CVE-2023-40076: In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials fr In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20081P4MEDIUMCVSS 5.9v10.0v11.0+1 more2022-04-11
CVE-2022-20081 [MEDIUM] CWE-295 CVE-2022-20081: In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID: ALPS06461919.
nvd
CVE-2016-6680P4HIGHCVSS 7.8≤ 7.02016-10-10
CVE-2016-6680 [HIGH] CWE-200 CVE-2016-6680: CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X a CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain sensitive information via a crafted application that makes an iw_set_priv ioctl call, aka Android internal bug 29982678 and Qualcomm internal bug CR 1048052.
nvd
CVE-2015-8889P4HIGHCVSS 7.8≤ 6.0.12016-07-11
CVE-2015-8889 [HIGH] CWE-264 CVE-2015-8889: The aboot implementation in the Qualcomm components in Android before 2016-07-05 on Nexus 6P devices The aboot implementation in the Qualcomm components in Android before 2016-07-05 on Nexus 6P devices omits the recovery PIN feature, which has unspecified impact and attack vectors, aka Android internal bug 28822677 and Qualcomm internal bug CR804067.
nvd
CVE-2014-9863P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9863 [HIGH] CWE-190 CVE-2014-9863: Integer underflow in the diag driver in the Qualcomm components in Android before 2016-08-05 on Nexu Integer underflow in the diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal bug 28768146 and Qualcomm internal bug CR549470.
nvd
CVE-2012-4220P4MEDIUMCVSS 6.8v2.3v2.3.1+20 more2012-11-30
CVE-2012-4220 [MEDIUM] CVE-2012-4220: diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver f diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments in a local diagchar_ioctl call.
nvd
CVE-2014-9873P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2014-9873 [HIGH] CWE-264 CVE-2014-9873: Integer underflow in drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016- Integer underflow in drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal bug 28750726 and Qualcomm internal bug CR556860.
nvd
Google Android vulnerabilities | cvebase