Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 182 of 339
CVE-2023-32854P4MEDIUMCVSS 6.7v11.0v12.02023-12-04
CVE-2023-32854 [MEDIUM] CWE-787 CVE-2023-32854: In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08240132; Issue ID: ALPS08240132.
nvd
CVE-2023-32866P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-12-04
CVE-2023-32866 [MEDIUM] CWE-787 CVE-2023-32866: In mmp, there is a possible memory corruption due to an incorrect bounds check. This could lead to l
In mmp, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342152; Issue ID: ALPS07342152.
nvd
CVE-2023-32853P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32853 [MEDIUM] CWE-787 CVE-2023-32853: In rpmb, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In rpmb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648764; Issue ID: ALPS07648764.
nvd
CVE-2023-32868P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32868 [MEDIUM] CWE-787 CVE-2023-32868: In display drm, there is a possible out of bounds write due to a missing bounds check. This could le
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Issue ID: ALPS07363632.
nvd
CVE-2023-32864P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32864 [MEDIUM] CWE-787 CVE-2023-32864: In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could
In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07292187; Issue ID: ALPS07292187.
nvd
CVE-2023-32867P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32867 [MEDIUM] CWE-787 CVE-2023-32867: In display drm, there is a possible out of bounds write due to a missing bounds check. This could le
In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560793; Issue ID: ALPS07560793.
nvd
CVE-2023-20772P4MEDIUMCVSS 6.7v12.0v13.02023-07-04
CVE-2023-20772 [MEDIUM] CWE-862 CVE-2023-20772: In vow, there is a possible escalation of privilege due to a missing permission check. This could le
In vow, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441796; Issue ID: ALPS07441796.
nvd
CVE-2023-48405P4MEDIUMCVSS 6.7vAndroid kernel2023-12-08
CVE-2023-48405 [MEDIUM] CVE-2023-48405: there is a possible way for the secure world to write to NS memory due to a logic error in the code.
there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20754P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-07-04
CVE-2023-20754 [MEDIUM] CWE-787 CVE-2023-20754: In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead t
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07588343.
nvd
CVE-2024-20001P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-02-05
CVE-2024-20001 [MEDIUM] CWE-787 CVE-2024-20001: In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID: DTV03961601.
nvd
CVE-2023-32855P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32855 [MEDIUM] CWE-862 CVE-2023-32855: In aee, there is a possible escalation of privilege due to a missing permission check. This could le
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
nvd
CVE-2023-48406P4MEDIUMCVSS 6.7vAndroid kernel2023-12-08
CVE-2023-48406 [MEDIUM] CWE-269 CVE-2023-48406: there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic er
there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-32849P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-12-04
CVE-2023-32849 [MEDIUM] CWE-787 CVE-2023-32849: In cmdq, there is a possible out of bounds write due to type confusion. This could lead to local esc
In cmdq, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161758; Issue ID: ALPS08161758.
nvd
CVE-2023-32848P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-12-04
CVE-2023-32848 [MEDIUM] CWE-787 CVE-2023-32848: In vdec, there is a possible out of bounds write due to type confusion. This could lead to local esc
In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.
nvd
CVE-2022-26461P4MEDIUMCVSS 6.7v11.0v12.02022-09-06
CVE-2022-26461 [MEDIUM] CWE-670 CVE-2022-26461: In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escala
In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032604; Issue ID: ALPS07032604.
nvd
CVE-2026-20414P4MEDIUMCVSS 6.7v15.02026-02-02
CVE-2026-20414 [MEDIUM] CWE-416 CVE-2026-20414: In imgsys, there is a possible escalation of privilege due to use after free. This could lead to loc
In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362999; Issue ID: MSV-5625.
nvd
CVE-2026-20410P4MEDIUMCVSS 6.7v15.02026-02-02
CVE-2026-20410 [MEDIUM] CWE-787 CVE-2026-20410: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362552; Issue ID: MSV-5760.
nvd
CVE-2026-20413P4MEDIUMCVSS 6.7v15.02026-02-02
CVE-2026-20413 [MEDIUM] CWE-1285 CVE-2026-20413: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362725; Issue ID: MSV-5694.
nvd
CVE-2023-20696P4MEDIUMCVSS 6.7v13.02023-05-15
CVE-2023-20696 [MEDIUM] CWE-787 CVE-2023-20696: In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07856356 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07856356 / ALPS07874388 (For MT6880 and MT689
nvd
CVE-2023-21018P4MEDIUMCVSS 6.7v13.0vAndroid-132023-03-24
CVE-2023-21018 [MEDIUM] CWE-416 CVE-2023-21018: In UnwindingWorker of unwinding.cc, there is a possible out of bounds write due to a use after free.
In UnwindingWorker of unwinding.cc, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233338564
nvd