cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 17 of 339
CVE-2018-9373P3HIGHCVSS 8.8vAndroid Kernel2025-01-28
CVE-2018-9373 [HIGH] CWE-787 CVE-2018-9373: In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a miss In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21273P3HIGHCVSS 8.8v11.0v12.0+6 more2023-08-14
CVE-2023-21273 [HIGH] CWE-787 CVE-2023-21273: In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9475P3HIGHCVSS 8.8v7.0v7.1.1+9 more2024-11-20
CVE-2018-9475 [HIGH] CWE-787 CVE-2018-9475: In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due t In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation of privilege via Bluetooth, if the recipient has enabled SIP calls with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21356P3HIGHCVSS 8.8v14.0v142023-10-30
CVE-2023-21356 [HIGH] CWE-787 CVE-2023-21356: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-31710P3HIGHCVSS 8.4v13.0v14.0+1 more2025-06-03
CVE-2025-31710 [HIGH] CWE-77 CVE-2025-31710: In engineermode service, there is a possible command injection due to improper input validation. Thi In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
nvd
CVE-2016-0816P3CRITICALCVSS 9.8v6.0v6.0.12016-03-12
CVE-2016-0816 [CRITICAL] CWE-119 CVE-2016-0816: mediaserver in Android 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or ca mediaserver in Android 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to decoder/ih264d_parse_islice.c and decoder/ih264d_parse_pslice.c, aka internal bug 25928803.
nvdosv
CVE-2026-0038P3HIGHCVSS 8.4vAndroid kernel2026-03-02
CVE-2026-0038 [HIGH] CVE-2026-0038: In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a l In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-6636P3CRITICALCVSS 9.8v5.0v5.1.1+2 more2016-01-06
CVE-2015-6636 [CRITICAL] CWE-119 CVE-2015-6636: mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.
nvd
CVE-2016-2429P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-05-09
CVE-2016-2429 [CRITICAL] CWE-119 CVE-2016-2429: libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x befor libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not prevent free operations on uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted media file, aka internal bug 27211
nvd
CVE-2016-0837P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-0837 [CRITICAL] CWE-119 CVE-2016-0837: MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via a crafted media file, aka internal bug 27208621.
nvd
CVE-2016-0804P3CRITICALCVSS 9.8v5.0v5.0.1+6 more2016-02-07
CVE-2016-0804 [CRITICAL] CWE-119 CVE-2016-0804: The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplay The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 improperly manages mDrmManagerClient objects, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via
nvd
CVE-2015-3876P3CRITICALCVSS 9.3≤ 5.1.12015-10-02
CVE-2015-3876 [CRITICAL] CWE-20 CVE-2015-3876: libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.
nvd
CVE-2018-21072P3CRITICALCVSS 9.8v6.0v7.0+4 more2020-04-08
CVE-2018-21072 [CRITICAL] CWE-125 CVE-2018-21072: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos chipsets) software. A kernel driver allows out-of-bounds Read/Write operations and possibly arbitrary code execution. The Samsung ID is SVE-2018-11358 (May 2018).
nvd
CVE-2018-21055P3CRITICALCVSS 9.8v7.02020-04-08
CVE-2018-21055 [CRITICAL] CWE-20 CVE-2018-21055: An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipset An issue was discovered on Samsung mobile devices with N(7.0) (Qualcomm models using MSM8996 chipsets) software. A device can be rooted with a custom image to execute arbitrary scripts in the INIT context. The Samsung ID is SVE-2018-11940 (September 2018).
nvd
CVE-2021-25386P3CRITICALCVSS 9.8v8.1v9.0+2 more2021-06-11
CVE-2021-25386 [CRITICAL] CWE-121 CVE-2021-25386: An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
nvd
CVE-2021-25385P3CRITICALCVSS 9.8v8.1v9.0+2 more2021-06-11
CVE-2021-25385 [CRITICAL] CWE-121 CVE-2021-25385: An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
nvd
CVE-2021-25383P3CRITICALCVSS 9.8v8.1v9.0+2 more2021-06-11
CVE-2021-25383 [CRITICAL] CWE-122 CVE-2021-25383: An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
nvd
CVE-2020-11873P3CRITICALCVSS 9.8v7.2v8.0+3 more2020-04-17
CVE-2020-11873 [CRITICAL] CWE-787 CVE-2020-11873: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A st An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer overflow in the logging tool could allow an attacker to gain privileges. The LG ID is LVE-SMP-200005 (April 2020).
nvd
CVE-2022-23425P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-02-11
CVE-2022-23425 [CRITICAL] CWE-20 CVE-2022-23425: Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to sen Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.
nvd
CVE-2025-36904P3CRITICALCVSS 9.8vAndroid kernel2025-09-04
CVE-2025-36904 [CRITICAL] CWE-269 CVE-2025-36904: WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-39645 WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.
nvd
Google Android vulnerabilities | cvebase