cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 168 of 339
CVE-2016-6696P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-6696 [CRITICAL] CWE-20 CVE-2016-6696: sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm internal bug CR 1041130.
nvd
CVE-2019-20602P4HIGHCVSS 7.5v7.0v7.1.0+4 more2020-03-24
CVE-2019-20602 [HIGH] CWE-476 CVE-2019-20602: An issue was discovered on Samsung mobile devices with N(7.x), O(8.0), and P(9.0) (Qualcomm chipsets An issue was discovered on Samsung mobile devices with N(7.x), O(8.0), and P(9.0) (Qualcomm chipsets) software. The Authnr Trustlet has a NULL pointer dereference. The Samsung ID is SVE-2019-13949 (May 2019).
nvd
CVE-2019-20603P4HIGHCVSS 7.5v7.0v7.1.0+4 more2020-03-24
CVE-2019-20603 [HIGH] CWE-476 CVE-2019-20603: An issue was discovered on Samsung mobile devices with N(7.x), O(8.0), and P(9.0) (Qualcomm chipsets An issue was discovered on Samsung mobile devices with N(7.x), O(8.0), and P(9.0) (Qualcomm chipsets) software. The ESECOMM Trustlet has a NULL pointer dereference. The Samsung ID is SVE-2019-13950 (May 2019).
nvd
CVE-2017-13301P4HIGHCVSS 7.5v8.02018-04-04
CVE-2017-13301 [HIGH] CWE-20 CVE-2017-13301: A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0 A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-66498711.
nvd
CVE-2017-13302P4HIGHCVSS 7.5v8.02018-04-04
CVE-2017-13302 [HIGH] CWE-20 CVE-2017-13302: A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0 A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-69969749.
nvd
CVE-2017-0845P4HIGHCVSS 7.5v5.0v5.0.1+10 more2017-11-16
CVE-2017-0845 [HIGH] CWE-732 CVE-2017-0845: A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Ve A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35028827.
nvd
CVE-2018-21088P4HIGHCVSS 7.5v7.0v7.1.0+2 more2020-04-08
CVE-2018-21088 [HIGH] CWE-755 CVE-2018-21088: An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a rebo An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a reboot because InputMethodManagerService has an unprotected system service. The Samsung ID is SVE-2017-9995 (January 2018).
nvd
CVE-2016-11031P4HIGHCVSS 7.5v4.4v5.0+2 more2020-04-07
CVE-2016-11031 [HIGH] CWE-20 CVE-2016-11031: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. Ant An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. The Samsung ID is SVE-2016-7044 (November 2016).
nvd
CVE-2017-18685P4HIGHCVSS 7.5v4.4v5.0+2 more2020-04-07
CVE-2017-18685 [HIGH] CWE-20 CVE-2017-18685: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash via a malformed serializable object in an Intent. The Samsung ID is SVE-2016-7123 (February 2017).
nvd
CVE-2019-20577P4HIGHCVSS 7.5v9.02020-03-24
CVE-2019-20577 [HIGH] CVE-2019-20577: An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The MALI G An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The MALI GPU Driver allows a kernel panic. The Samsung ID is SVE-2019-14372 (August 2019).
nvd
CVE-2017-13300P4HIGHCVSS 7.5v6.0v6.0.12018-04-04
CVE-2017-13300 [HIGH] CWE-20 CVE-2017-13300: A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versio A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1. Android ID: A-71567394.
nvd
CVE-2017-0852P4HIGHCVSS 7.5v5.0.2v5.1.1+1 more2017-11-16
CVE-2017-0852 [HIGH] CWE-787 CVE-2017-0852: A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versio A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0. Android ID: A-62815506.
nvd
CVE-2016-3877P4CRITICALCVSS 9.8≤ 7.02016-09-11
CVE-2016-3877 [CRITICAL] CVE-2016-3877: Unspecified vulnerability in Android before 2016-09-01 has unknown impact and attack vectors. Unspecified vulnerability in Android before 2016-09-01 has unknown impact and attack vectors.
nvd
CVE-2017-18675P4HIGHCVSS 7.5v6.0v7.0+3 more2020-04-07
CVE-2017-18675 [HIGH] CWE-772 CVE-2017-18675: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 c An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April 2017).
nvd
CVE-2014-9940P4HIGHCVSS 7.0≤ 7.1.12017-05-02
CVE-2014-9940 [HIGH] CWE-416 CVE-2014-9940: The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 all The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
nvd
CVE-2019-20599P4HIGHCVSS 7.5v7.0v7.1.0+5 more2020-03-24
CVE-2019-20599 [HIGH] CWE-862 CVE-2019-20599: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Voice As An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Voice Assistant mishandles the notification audibility of a secured app. The Samsung ID is SVE-2018-13326 (May 2019).
nvd
CVE-2017-0444P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0444 [HIGH] CVE-2017-0444: An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious a An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-32705232.
nvd
CVE-2017-0433P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0433 [HIGH] CVE-2017-0433: An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local mal An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31913571.
nvd
CVE-2017-0439P4HIGHCVSS 7.0≤ 7.1.12017-02-08
CVE-2017-0439 [HIGH] CWE-120 CVE-2017-0439: An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32450647. References: QC-CR
nvd
CVE-2017-0443P4HIGHCVSS 7.0v7.1.12017-02-08
CVE-2017-0443 [HIGH] CVE-2017-0443: An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877494. References: QC-CR#1092497
nvd
Google Android vulnerabilities | cvebase