cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 178 of 339
CVE-2017-18650P4HIGHCVSS 7.5v7.0v7.1.0+2 more2020-04-07
CVE-2017-18650 [HIGH] CWE-754 CVE-2017-18650: An issue was discovered on Samsung mobile devices with N(7.x) software. There is a WifiStateMachine An issue was discovered on Samsung mobile devices with N(7.x) software. There is a WifiStateMachine IllegalArgumentException and reboot if a malformed wpa_supplicant.conf is read. The Samsung ID is SVE-2017-9828 (October 2017).
nvd
CVE-2019-20604P4HIGHCVSS 7.5v8.0v8.12020-03-24
CVE-2019-20604 [HIGH] CVE-2019-20604: An issue was discovered on Samsung mobile devices with O(8.x) software. Attackers can disable Galler An issue was discovered on Samsung mobile devices with O(8.x) software. Attackers can disable Gallery permanently. The Samsung ID is SVE-2019-14031 (May 2019).
nvd
CVE-2012-4221P4MEDIUMCVSS 6.8v2.3v2.3.1+20 more2012-11-30
CVE-2012-4221 [MEDIUM] CWE-189 CVE-2012-4221: Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service via an application that uses crafted arguments in a local diagchar_ioctl call.
nvd
CVE-2014-8609P4HIGHCVSS 7.2≤ 4.4.4v4.0+15 more2014-12-15
CVE-2014-8609 [HIGH] CWE-264 CVE-2014-8609: The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings a The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted app
nvd
CVE-2015-8955P4HIGHCVSS 7.3v7.02016-10-10
CVE-2015-8955 [HIGH] CWE-264 CVE-2015-8955: arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.
nvd
CVE-2015-3860P4HIGHCVSS 7.2≤ 5.12015-10-01
CVE-2015-3860 [HIGH] CWE-284 CVE-2015-3860: packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LM packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access restrictions via a long password that triggers a SystemUI crash, aka internal bug 22214934.
nvd
CVE-2026-0151P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0151 CVE-2026-0151: In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflo In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0154P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0154 CVE-2026-0154: In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0161P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0161 CVE-2026-0161: In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0963P4HIGHCVSS 7.1v9.0v10.0+3 more2021-12-15
CVE-2021-0963 [HIGH] CWE-1021 CVE-2021-0963: In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in ke In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9An
nvd
CVE-2022-33731P4HIGHCVSS 7.1v11.0v12.02022-08-05
CVE-2022-33731 [HIGH] CWE-284 CVE-2022-33731: Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows atta Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.
nvd
CVE-2022-20007P4HIGHCVSS 7.0v10.0v11.0+3 more2022-05-10
CVE-2022-20007 [HIGH] CWE-362 CVE-2022-20007: In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: A
nvd
CVE-2017-9697P4HIGHCVSS 7.0v8.02017-10-10
CVE-2017-9697 [HIGH] CWE-362 CVE-2017-9697: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while reading command registration table entries in diag_dbgfs_read_table.
nvd
CVE-2022-27834P4HIGHCVSS 7.0v10.0v11.0+1 more2022-04-11
CVE-2022-27834 [HIGH] CWE-367 CVE-2022-27834: Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-202 Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.
nvd
CVE-2018-9502P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9502 [MEDIUM] CWE-125 CVE-2018-9502: In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missi In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.
nvd
CVE-2021-0662P4MEDIUMCVSS 6.7v9.0v10.0+1 more2021-10-25
CVE-2021-0662 [MEDIUM] CWE-787 CVE-2021-0662: In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could l In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844434; Issue ID: ALPS05844434.
nvd
CVE-2021-0661P4MEDIUMCVSS 6.7v9.0v10.0+1 more2021-10-25
CVE-2021-0661 [MEDIUM] CWE-787 CVE-2021-0661: In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could l In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844413; Issue ID: ALPS05844413.
nvd
CVE-2021-0663P4MEDIUMCVSS 6.7v9.0v10.0+1 more2021-10-25
CVE-2021-0663 [MEDIUM] CWE-787 CVE-2021-0663: In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could l In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844458; Issue ID: ALPS05844458.
nvd
CVE-2022-20313P4MEDIUMCVSS 6.8v13.0vAndroid-132022-08-12
CVE-2022-20313 [MEDIUM] CWE-787 CVE-2022-20313: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-192206329
nvd
CVE-2023-20926P4MEDIUMCVSS 6.8v12.0v12.1+2 more2023-03-24
CVE-2023-20926 [MEDIUM] CWE-862 CVE-2023-20926: In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory res In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitati
nvd
Google Android vulnerabilities | cvebase