cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 174 of 339
CVE-2019-9352P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9352 [MEDIUM] CWE-20 CVE-2019-9352: In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-124253062
nvd
CVE-2021-25469P4MEDIUMCVSS 6.7v10.0v11.02021-10-06
CVE-2021-25469 [MEDIUM] CWE-120 CVE-2021-25469: A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Rele A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.
nvd
CVE-2022-20108P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-03
CVE-2022-20108 [MEDIUM] CWE-787 CVE-2022-20108: In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330702; Issue ID: DTV03330702.
nvd
CVE-2022-20106P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-03
CVE-2022-20106 [MEDIUM] CWE-787 CVE-2022-20106: In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This cou In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.
nvd
CVE-2022-20105P4MEDIUMCVSS 6.7v9.0v10.0+1 more2022-05-03
CVE-2022-20105 [MEDIUM] CWE-787 CVE-2022-20105: In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This co In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.
nvd
CVE-2021-25396P4MEDIUMCVSS 6.7v10.0v11.02021-06-11
CVE-2021-25396 [MEDIUM] CWE-787 CVE-2021-25396: An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows ar An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2021-25475P4MEDIUMCVSS 6.7v10.0v11.02021-10-06
CVE-2021-25475 [MEDIUM] CWE-122 CVE-2021-25475: A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Relea A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2024-20022P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-03-04
CVE-2024-20022 [MEDIUM] CWE-125 CVE-2024-20022: In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255.
nvd
CVE-2023-32859P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32859 [MEDIUM] CWE-120 CVE-2023-32859: In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead In meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08000473; Issue ID: ALPS08000473.
nvd
CVE-2023-32860P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32860 [MEDIUM] CWE-120 CVE-2023-32860: In display, there is a possible classic buffer overflow due to a missing bounds check. This could le In display, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929788; Issue ID: ALPS07929788.
nvd
CVE-2023-32882P4MEDIUMCVSS 6.7v12.0v13.02024-01-02
CVE-2023-32882 [MEDIUM] CWE-787 CVE-2023-32882: In battery, there is a possible memory corruption due to a missing bounds check. This could lead to In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308616.
nvd
CVE-2024-20023P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-03-04
CVE-2024-20023 [MEDIUM] CWE-787 CVE-2024-20023: In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to loc In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638.
nvd
CVE-2023-21020P4MEDIUMCVSS 6.7v13.0vAndroid-132023-03-24
CVE-2023-21020 [MEDIUM] CWE-416 CVE-2023-21020: In registerSignalHandlers of main.c, there is a possible local arbitrary code execution due to a use In registerSignalHandlers of main.c, there is a possible local arbitrary code execution due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256591441
nvd
CVE-2025-20707P4MEDIUMCVSS 6.7v13.0v14.0+1 more2025-09-01
CVE-2025-20707 [MEDIUM] CWE-416 CVE-2025-20707: In geniezone, there is a possible memory corruption due to use after free. This could lead to local In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
nvd
CVE-2023-32812P4MEDIUMCVSS 6.7v13.02023-09-04
CVE-2023-32812 [MEDIUM] CWE-787 CVE-2023-32812: In gnss service, there is a possible out of bounds write due to improper input validation. This coul In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365; Issue ID: ALPS08017365.
nvd
CVE-2023-32891P4MEDIUMCVSS 6.7v11.0v12.0+1 more2024-01-02
CVE-2023-32891 [MEDIUM] CWE-787 CVE-2023-32891: In bluetooth service, there is a possible out of bounds write due to improper input validation. This In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07933038; Issue ID: MSV-559.
nvd
CVE-2023-20817P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20817 [MEDIUM] CWE-787 CVE-2023-20817: In wlan service, there is a possible out of bounds write due to improper input validation. This coul In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453600; Issue ID: ALPS07453600.
nvd
CVE-2023-20814P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20814 [MEDIUM] CWE-787 CVE-2023-20814: In wlan service, there is a possible out of bounds write due to improper input validation. This coul In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453560; Issue ID: ALPS07453560.
nvd
CVE-2023-20815P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20815 [MEDIUM] CWE-787 CVE-2023-20815: In wlan service, there is a possible out of bounds write due to improper input validation. This coul In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587; Issue ID: ALPS07453587.
nvd
CVE-2023-20816P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20816 [MEDIUM] CWE-787 CVE-2023-20816: In wlan service, there is a possible out of bounds write due to improper input validation. This coul In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589; Issue ID: ALPS07453589.
nvd
Google Android vulnerabilities | cvebase