cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 186 of 339
CVE-2024-20115P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20115 [MEDIUM] CWE-787 CVE-2024-20115: In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036695; Issue ID: MSV-1713.
nvd
CVE-2024-20118P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20118 [MEDIUM] CWE-123 CVE-2024-20118: In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062392; Issue ID: MSV-1621.
nvd
CVE-2024-20119P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20119 [MEDIUM] CWE-123 CVE-2024-20119: In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062301; Issue ID: MSV-1620.
nvd
CVE-2024-20120P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20120 [MEDIUM] CWE-787 CVE-2024-20120: In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1575.
nvd
CVE-2024-20113P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20113 [MEDIUM] CWE-787 CVE-2024-20113: In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036814; Issue ID: MSV-1715.
nvd
CVE-2024-20114P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20114 [MEDIUM] CWE-787 CVE-2024-20114: In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09037038; Issue ID: MSV-1714.
nvd
CVE-2024-20111P4MEDIUMCVSS 6.7v12.0v13.0+2 more2024-11-04
CVE-2024-20111 [MEDIUM] CWE-787 CVE-2024-20111: In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065033; Issue ID: MSV-1754.
nvd
CVE-2025-20769P4MEDIUMCVSS 6.7v14.0v15.0+1 more2025-12-02
CVE-2025-20769 [MEDIUM] CWE-121 CVE-2025-20769: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4804.
nvd
CVE-2026-20440P4MEDIUMCVSS 6.7v15.02026-03-02
CVE-2026-20440 [MEDIUM] CWE-1285 CVE-2026-20440: In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431968; Issue ID: MSV-5824.
nvd
CVE-2026-20441P4MEDIUMCVSS 6.7v15.02026-03-02
CVE-2026-20441 [MEDIUM] CWE-787 CVE-2026-20441: In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10432500; Issue ID: MSV-5803.
nvd
CVE-2025-20730P4MEDIUMCVSS 6.7v13.0v14.0+2 more2025-11-04
CVE-2025-20730 [MEDIUM] CWE-287 CVE-2025-20730: In preloader, there is a possible escalation of privilege due to an insecure default value. This cou In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.
nvd
CVE-2025-20783P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-01-06
CVE-2025-20783 [MEDIUM] CWE-787 CVE-2025-20783: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4684.
nvd
CVE-2021-0993P4MEDIUMCVSS 6.5v12.0vAndroid-122021-12-15
CVE-2021-0993 [MEDIUM] CVE-2021-0993: In getOffsetBeforeAfter of TextLine.java, there is a possible denial of service due to resource exha In getOffsetBeforeAfter of TextLine.java, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193849901
nvd
CVE-2024-0032P4MEDIUMCVSS 6.5v11.0v12.0+7 more2024-02-16
CVE-2024-0032 [MEDIUM] CWE-284 CVE-2024-0032: In multiple locations, there is a possible way to request access to directories that should be hidde In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-25450P4MEDIUMCVSS 6.5v8.1v9.0+2 more2021-09-09
CVE-2021-25450 [MEDIUM] CWE-20 CVE-2021-25450: Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attac Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
nvd
CVE-2018-9485P4MEDIUMCVSS 6.5v7.0v7.1.1+9 more2024-11-20
CVE-2018-9485 [MEDIUM] CWE-125 CVE-2018-9485: In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bou In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9480P4MEDIUMCVSS 6.5v8.0v8.1+3 more2024-11-20
CVE-2018-9480 [MEDIUM] CWE-125 CVE-2018-9480: In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper in In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9481P4MEDIUMCVSS 6.5v8.0v8.1+3 more2024-11-20
CVE-2018-9481 [MEDIUM] CWE-190 CVE-2018-9481: In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21315P4MEDIUMCVSS 6.5fixed in 14.0v142023-10-30
CVE-2023-21315 [MEDIUM] CWE-125 CVE-2023-21315: In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20693P4MEDIUMCVSS 6.5v13.0v14.0+1 more2025-07-08
CVE-2025-20693 [MEDIUM] CWE-125 CVE-2025-20693: In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This co In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421.
nvd
Google Android vulnerabilities | cvebase