cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 171 of 339
CVE-2023-20958P4HIGHCVSS 7.1v13.0vAndroid-132023-03-24
CVE-2023-20958 [HIGH] CWE-125 CVE-2023-20958: In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. Thi In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-254803162
nvd
CVE-2021-25388P4HIGHCVSS 7.1v11.02021-06-11
CVE-2021-25388 [HIGH] CWE-926 CVE-2021-25388: Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
nvd
CVE-2016-2059P4HIGHCVSS 7.0≤ 7.02016-05-05
CVE-2016-2059 [HIGH] CWE-269 CVE-2016-2059: The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allows attackers to gain privileges or cause a denial of serv
nvd
CVE-2018-9586P4HIGHCVSS 7.0v7.0v7.1.1+4 more2019-02-11
CVE-2018-9586 [HIGH] CWE-362 CVE-2018-9586: In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, it is possible that package verification is turned off and remains off due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit
nvd
CVE-2022-20082P4HIGHCVSS 7.0v10.0v11.0+1 more2022-07-06
CVE-2022-20082 [HIGH] CWE-362 CVE-2022-20082: In GPU, there is a possible use after free due to a race condition. This could lead to local escalat In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044730; Issue ID: ALPS07044730.
nvd
CVE-2022-20110P4HIGHCVSS 7.0v9.0v10.0+2 more2022-05-03
CVE-2022-20110 [HIGH] CWE-367 CVE-2022-20110: In ion, there is a possible use after free due to a race condition. This could lead to local escalat In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399901.
nvd
CVE-2019-2019P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2019-06-19
CVE-2019-2019 [MEDIUM] CWE-125 CVE-2019-2019: In ce_t4t_data_cback of ce_t4t.cc, there is a possible out-of-bound read due to a missing bounds che In ce_t4t_data_cback of ce_t4t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID
nvd
CVE-2019-9283P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9283 [MEDIUM] CWE-20 CVE-2019-9283: In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could l In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663564
nvd
CVE-2025-48618P4MEDIUMCVSS 6.8v13.0v14.0+6 more2025-12-08
CVE-2025-48618 [MEDIUM] CWE-667 CVE-2025-48618: In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from t In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0356P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-03
CVE-2021-0356 [MEDIUM] CWE-77 CVE-2021-0356: In netdiag, there is a possible command injection due to improper input validation. This could lead In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05442014.
nvd
CVE-2021-0358P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-03
CVE-2021-0358 [MEDIUM] CWE-77 CVE-2021-0358: In netdiag, there is a possible command injection due to improper input validation. This could lead In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05442022.
nvd
CVE-2020-0351P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0351 [MEDIUM] CWE-20 CVE-2020-0351: In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lea In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777537
nvd
CVE-2019-2022P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2019-06-19
CVE-2019-2022 [MEDIUM] CWE-125 CVE-2019-2022: In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of- In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Andro
nvd
CVE-2019-2020P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2019-06-19
CVE-2019-2020 [MEDIUM] CWE-125 CVE-2019-2020: In llcp_dlc_proc_rr_rnr_pdu of llcp_dlc.cc, there is a possible out-of-bound read due to a missing b In llcp_dlc_proc_rr_rnr_pdu of llcp_dlc.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Andr
nvd
CVE-2020-0172P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0172 [MEDIUM] CWE-20 CVE-2020-0172: In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. Thi In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127312550
nvd
CVE-2020-0171P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0171 [MEDIUM] CWE-20 CVE-2020-0171: In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. Th In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127313223
nvd
CVE-2020-0174P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0174 [MEDIUM] CWE-20 CVE-2020-0174: In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. Th In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127313537
nvd
CVE-2017-13257P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-04-04
CVE-2017-13257 [MEDIUM] CWE-416 CVE-2017-13257: In bta_pan_data_buf_ind_cback of bta_pan_act.cc there is a use after free that can result in an out In bta_pan_data_buf_ind_cback of bta_pan_act.cc there is a use after free that can result in an out of bounds read of memory allocated via malloc. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0,
nvd
CVE-2018-9563P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2019-06-19
CVE-2018-9563 [MEDIUM] CWE-125 CVE-2018-9563: In llcp_util_parse_cc of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds In llcp_util_parse_cc of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Androi
nvd
CVE-2019-2021P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2019-06-19
CVE-2019-2021 [MEDIUM] CWE-125 CVE-2019-2021: In rw_t3t_act_handle_ndef_detect_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a mi In rw_t3t_act_handle_ndef_detect_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
Google Android vulnerabilities | cvebase