Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 2 of 339
CVE-2015-1805P2HIGHCVSS 7.2Exploitedv4.4.3v5.0.1+3 more2015-08-08
CVE-2015-1805 [HIGH] CWE-17 CVE-2015-1805: The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector ar
nvd
CVE-2013-7372P2MEDIUMCVSS 5.0Exploited≤ 4.3.1v4.0+10 more2014-04-29
CVE-2013-7372 [MEDIUM] CWE-310 CVE-2013-7372: The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/se
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Architecture (JCA) in Android before 4.4 and other products, when no seed is provided by the user,
nvd
CVE-2015-1538P2CRITICALCVSS 10.0PoC≤ 5.12015-10-01
CVE-2015-1538 [CRITICAL] CWE-189 CVE-2015-1538: Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagef
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.
nvd
CVE-2015-3864P2CRITICALCVSS 10.0PoC≤ 5.12015-10-01
CVE-2015-3864 [CRITICAL] CVE-2015-3864: Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
nvd
CVE-2013-4787P2CRITICALCVSS 9.3PoCv1.6v2.0+29 more2013-07-09
CVE-2013-4787 [CRITICAL] CWE-310 CVE-2013-4787: Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applic
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which o
nvd
CVE-2021-0889P3CRITICALCVSS 9.8Exploitedv8.1v9.0+4 more2021-12-15
CVE-2021-0889 [CRITICAL] CVE-2021-0889: In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow.
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296
nvd
CVE-2016-0801P2CRITICALCVSS 9.8PoCv4.4.4v5.0+3 more2016-02-07
CVE-2016-0801 [CRITICAL] CWE-20 CVE-2016-0801: The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
nvd
CVE-2016-2107P2MEDIUMCVSS 5.9PoCv4.0v4.0.1+18 more2016-05-05
CVE-2016-2107 [MEDIUM] CVE-2016-2107: The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
nvd
CVE-2021-0956P3CRITICALCVSS 9.8Exploitedv11.0v12.0+1 more2021-12-15
CVE-2021-0956 [CRITICAL] CWE-787 CVE-2021-0956: In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write
In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-18994
nvd
CVE-2017-14496P2HIGHCVSS 7.5PoCv4.4.4v5.0.2+7 more2017-10-03
CVE-2017-14496 [HIGH] CWE-191 CVE-2017-14496: Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --ad
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
nvd
CVE-2013-4710P2CRITICALCVSS 9.3PoCv3.0v3.1+12 more2014-03-03
CVE-2013-4710 [CRITICAL] CVE-2013-4710: Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices d
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a relat
nvd
CVE-2017-0781P2HIGHCVSS 8.8PoCv4.0v4.0.1+28 more2017-09-14
CVE-2017-0781 [HIGH] CWE-119 CVE-2017-0781: A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions:
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.
nvd
CVE-2019-2107P2HIGHCVSS 8.8PoCv7.0v7.1.1+5 more2019-07-08
CVE-2019-2107 [HIGH] CWE-787 CVE-2019-2107: In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a miss
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.
nvd
CVE-2016-6754P2HIGHCVSS 8.8PoC≤ 6.0.1v5.0+4 more2016-11-25
CVE-2016-6754 [HIGH] CWE-74 CVE-2016-6754: A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1,
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.
nvd
CVE-2016-2108P2CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-05-05
CVE-2016-2108 [CRITICAL] CWE-119 CVE-2016-2108: The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.
nvd
CVE-2016-2417P3CRITICALCVSS 9.8PoCv4.0v4.0.1+20 more2016-04-18
CVE-2016-2417 [CRITICAL] CWE-264 CVE-2016-2417: media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demo
nvd
CVE-2015-3824P2CRITICALCVSS 10.0≤ 5.12015-10-01
CVE-2015-3824 [CRITICAL] CWE-119 CVE-2015-3824: The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via a crafted MPEG-4 tx3g atom, aka internal bug 20923261.
nvd
CVE-2017-13260P3HIGHCVSS 7.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13260 [HIGH] CWE-125 CVE-2017-13260: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177251.
nvd
CVE-2017-13261P3HIGHCVSS 7.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13261 [HIGH] CWE-125 CVE-2017-13261: In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a mis
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID:
nvd
CVE-2017-13258P3HIGHCVSS 7.5PoCv5.1.1v6.0+6 more2018-04-04
CVE-2017-13258 [HIGH] CWE-125 CVE-2017-13258: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67863755.
nvd