Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 187 of 339
CVE-2018-9482P4MEDIUMCVSS 6.5v8.0v8.1+3 more2024-11-20
CVE-2018-9482 [MEDIUM] CWE-190 CVE-2018-9482: In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflo
In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43766P4MEDIUMCVSS 6.5v14.0v15.0+4 more2026-03-02
CVE-2024-43766 [MEDIUM] CWE-319 CVE-2024-43766: In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invali
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0005P4MEDIUMCVSS 6.2v14.0v15.0+4 more2026-03-02
CVE-2026-0005 [MEDIUM] CWE-200 CVE-2026-0005: In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of interaction and impact is app-dependent with no additional execution priv
nvd
CVE-2019-9414P4MEDIUMCVSS 5.9v10.0vAndroid-102019-09-27
CVE-2019-9414 [MEDIUM] CWE-20 CVE-2019-9414: In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validat
In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android
nvd
CVE-2024-20024P4MEDIUMCVSS 6.0v12.0v13.0+1 more2024-03-04
CVE-2024-20024 [MEDIUM] CWE-787 CVE-2024-20024: In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to loc
In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541635; Issue ID: ALPS08541635.
nvd
CVE-2024-32897P4MEDIUMCVSS 5.9vAndroid kernel2024-06-13
CVE-2024-32897 [MEDIUM] CWE-125 CVE-2024-32897: In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out
In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2026-0075P4MEDIUMCVSS 5.9v14.0v15.0+8 more2026-06-01
CVE-2026-0075 [MEDIUM] CWE-89 CVE-2026-0075: In multiple functions, there is a possible way to access the contacts database due to a SQL injectio
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2014-3100P4MEDIUMCVSS 5.1v4.32014-07-02
CVE-2014-3100 [MEDIUM] CWE-119 CVE-2014-3100: Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore servi
Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on cryptographic operations, via a long key name.
nvd
CVE-2016-3854P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2016-3854 [HIGH] CWE-125 CVE-2016-3854: drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does
drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR897326.
nvd
CVE-2024-20147P4MEDIUMCVSS 5.3v13.0v14.0+1 more2025-02-03
CVE-2024-20147 [MEDIUM] CWE-617 CVE-2024-20147: In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This co
In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX chipsets) / ALPS09136501 (Note: For MT2737, MT3603, MT6XXX, and MT8XXX chip
nvd
CVE-2026-0136P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0136 CVE-2026-0136: In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to r
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-5856P4HIGHCVSS 7.0≤ 6.0.12017-04-12
CVE-2016-5856 [HIGH] CWE-264 CVE-2016-5856: Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.
nvd
CVE-2017-18680P4HIGHCVSS 7.1v5.0v5.1+1 more2020-04-07
CVE-2017-18680 [HIGH] CWE-20 CVE-2017-18680: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interface allows Add User actions, leading to an unintended ability to access user data in external storage. The Samsung ID is SVE-2016-7797 (March 2017).
nvd
CVE-2019-20600P4HIGHCVSS 7.1v8.0v9.02020-03-24
CVE-2019-20600 [HIGH] CWE-416 CVE-2019-20600: An issue was discovered on Samsung mobile devices with O(8.0) and P(9.0) (Exynos8890 chipsets) softw
An issue was discovered on Samsung mobile devices with O(8.0) and P(9.0) (Exynos8890 chipsets) software. A use-after-free occurs in the MALI GPU driver. The Samsung ID is SVE-2019-13921-1 (May 2019).
nvd
CVE-2022-23427P4HIGHCVSS 7.1v10.0v11.0+1 more2022-02-11
CVE-2022-23427 [HIGH] CWE-20 CVE-2022-23427: PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 a
PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.
nvd
CVE-2022-33732P4HIGHCVSS 7.1v12.02022-08-05
CVE-2022-33732 [HIGH] CWE-287 CVE-2022-33732: Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows l
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.
nvd
CVE-2020-0204P4HIGHCVSS 7.0v10.0vAndroid-102020-06-11
CVE-2020-0204 [HIGH] CWE-367 CVE-2020-0204: In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of C
In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS update with no additional execution privileges needed. User interaction is needed for exploitation.Product:
nvd
CVE-2016-3757P4HIGHCVSS 7.0v4.0v4.0.1+20 more2016-07-11
CVE-2016-3757 [HIGH] CWE-20 CVE-2016-3757: The print_maps function in toolbox/lsof.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x bef
The print_maps function in toolbox/lsof.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows user-assisted attackers to gain privileges via a crafted application that attempts to list a long name of a memory-mapped file, aka internal bug 28175237. NOTE: print_maps is not related to the Vic Abell lsof pro
nvd
CVE-2021-0308P4MEDIUMCVSS 6.8v8.0v8.1+8 more2021-01-11
CVE-2021-0308 [MEDIUM] CWE-787 CVE-2021-0308: In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID:
nvd
CVE-2017-10709P4MEDIUMCVSS 6.8v6.02017-06-30
CVE-2017-10709 [MEDIUM] CWE-287 CVE-2017-10709: The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.
nvd