Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 19 of 339
CVE-2023-35684P3HIGHCVSS 8.8v11.0v12.0+6 more2023-09-11
CVE-2023-35684 [HIGH] CWE-787 CVE-2023-35684: In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-0838P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-0838 [CRITICAL] CWE-119 CVE-2016-0838: Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x
Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a negative number of samples, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to arm-wt-22k/lib_src/eas_wtengine.c and arm-w
nvd
CVE-2015-3873P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3873 [CRITICAL] CWE-119 CVE-2015-3873: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23016072, 23248776, 23247055, 22845824, 22008959, 21814993, 21048776, 20718524, 20674674, 22388975, 20674086, 21443020, and 22077698, a different vulnerability th
nvd
CVE-2015-7889P4MEDIUMCVSS 5.5PoC≤ 5.1.12017-12-28
CVE-2015-7889 [MEDIUM] CWE-275 CVE-2015-7889: The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR use
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensitive information via a crafted application that sends a
nvd
CVE-2016-6689P4MEDIUMCVSS 5.5PoC≤ 7.02016-10-10
CVE-2016-6689 [MEDIUM] CWE-200 CVE-2016-6689: Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensit
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347.
nvd
CVE-2016-3840P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-08-05
CVE-2016-3840 [CRITICAL] CWE-264 CVE-2016-3840: Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-0
Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.
nvd
CVE-2016-0839P3CRITICALCVSS 9.8v6.0v6.0.12016-04-18
CVE-2016-0839 [CRITICAL] CWE-119 CVE-2016-0839: post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effec
post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25753245.
nvd
CVE-2016-0841P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-0841 [CRITICAL] CWE-119 CVE-2016-0841: media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5
media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26040840.
nvd
CVE-2015-6602P3CRITICALCVSS 9.3≤ 5.1.12015-10-02
CVE-2015-6602 [CRITICAL] CWE-20 CVE-2015-6602: libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via craft
libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.
nvd
CVE-2011-2357P4MEDIUMCVSS 4.3PoCv2.3.4v3.12011-08-12
CVE-2011-2357 [MEDIUM] CWE-20 CVE-2011-2357: Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startAc
nvd
CVE-2025-36923P3HIGHCVSS 8.0vAndroid kernel2025-12-11
CVE-2025-36923 [HIGH] CWE-122 CVE-2025-36923: In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds
In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-25278P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-09-11
CVE-2020-25278 [CRITICAL] CWE-787 CVE-2020-25278: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Qur
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung IDs are SVE-2020-18088, SVE-2020-18225, SVE-2020-18301 (September 2020).
nvd
CVE-2025-0093P3HIGHCVSS 7.5v12.0v12.1+8 more2025-08-26
CVE-2025-0093 [HIGH] CWE-732 CVE-2025-0093: In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-25449P3CRITICALCVSS 9.8v8.1v9.0+2 more2021-09-09
CVE-2021-25449 [CRITICAL] CWE-122 CVE-2021-25449: An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release
An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.
nvd
CVE-2023-35647P3CRITICALCVSS 9.8vAndroid kernel2023-10-11
CVE-2023-35647 [CRITICAL] CWE-125 CVE-2023-35647: In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of
In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-35648P3CRITICALCVSS 9.8vAndroid kernel2023-10-11
CVE-2023-35648 [CRITICAL] CWE-125 CVE-2023-35648: In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of
In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2021-0340P3HIGHCVSS 8.8v10.0vAndroid-102021-02-10
CVE-2021-0340 [HIGH] CWE-212 CVE-2021-0340: In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information du
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-134155286
nvd
CVE-2016-0802P3HIGHCVSS 8.8v4.4.4v5.0+3 more2016-02-07
CVE-2016-0802 [HIGH] CWE-20 CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
nvd
CVE-2019-1986P3HIGHCVSS 8.8v9.02019-02-28
CVE-2019-1986 [HIGH] CWE-787 CVE-2019-1986: In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a miss
In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege in system_server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-117838472.
nvd
CVE-2020-0002P3HIGHCVSS 8.8v8.0v8.1+6 more2020-01-08
CVE-2020-0002 [HIGH] CWE-416 CVE-2020-0002: In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after f
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142602711
nvd