cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 20 of 339
CVE-2019-2003P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2003 [HIGH] CWE-264 CVE-2019-2003: In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9And
nvd
CVE-2020-0449P3HIGHCVSS 8.8v8.0v8.1+4 more2020-11-10
CVE-2020-0449 [HIGH] CWE-416 CVE-2020-0449: In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-1
nvd
CVE-2018-9572P3HIGHCVSS 8.8v9.02018-12-07
CVE-2018-9572 [HIGH] CWE-787 CVE-2018-9572: In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116224432.
nvd
CVE-2022-20347P3HIGHCVSS 8.8v10.0v11.0+3 more2022-08-10
CVE-2022-20347 [HIGH] CWE-269 CVE-2022-20347: In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvd
CVE-2020-0190P3HIGHCVSS 8.8v10.0vAndroid-102020-06-11
CVE-2020-0190 [HIGH] CWE-787 CVE-2020-0190: In ideint_weave_blk of ideint_utils.c, there is a possible out of bounds write due to a heap buffer In ideint_weave_blk of ideint_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140324890
nvd
CVE-2019-9346P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-9346 [HIGH] CWE-787 CVE-2019-9346: In libstagefright, there is a possible out of bounds write due to a heap buffer overflow. This could In libstagefright, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128433933
nvd
CVE-2018-9529P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9529 [HIGH] CWE-787 CVE-2018-9529: In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due t In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112551874
nvd
CVE-2018-9528P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9528 [HIGH] CWE-787 CVE-2018-9528: In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write d In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112551721
nvd
CVE-2018-9534P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9534 [HIGH] CWE-787 CVE-2018-9534: In ixheaacd_mps_getstridemap of ixheaacd_mps_parse.c there is a possible out of bounds write due to In ixheaacd_mps_getstridemap of ixheaacd_mps_parse.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112857941
nvd
CVE-2018-9532P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9532 [HIGH] CWE-787 CVE-2018-9532: In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112765917
nvd
CVE-2018-9535P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9535 [HIGH] CWE-787 CVE-2018-9535: In ixheaacd_reset_acelp_data_fix of ixheaacd_lpc.c there is a possible out of bounds write due to a In ixheaacd_reset_acelp_data_fix of ixheaacd_lpc.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112858010
nvd
CVE-2018-9530P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9530 [HIGH] CWE-787 CVE-2018-9530: In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112609715
nvd
CVE-2020-0264P3HIGHCVSS 8.8v11.0vAndroid-112020-09-17
CVE-2020-0264 [HIGH] CWE-190 CVE-2020-0264: In libstagefright, there is a possible out of bounds write due to an integer overflow. This could le In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-116718596
nvd
CVE-2020-0131P3HIGHCVSS 8.8v10.0vAndroid-102020-06-11
CVE-2020-0131 [HIGH] CWE-787 CVE-2020-0131: In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely ini In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-151159638
nvd
CVE-2020-0168P3HIGHCVSS 8.8v10.0vAndroid-102020-06-11
CVE-2020-0168 [HIGH] CWE-787 CVE-2020-0168: In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv of impeg2_format_conv.c, there is a possible out of bounds In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv of impeg2_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137798382
nvd
CVE-2019-9291P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-9291 [HIGH] CWE-770 CVE-2019-9291: In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This c In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This could lead to remote code execution in Bluetooth with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112159179
nvd
CVE-2019-2063P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-2063 [HIGH] CWE-787 CVE-2019-2063: In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead t In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116019594
nvd
CVE-2017-13256P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-04-04
CVE-2017-13256 [HIGH] CWE-787 CVE-2017-13256: In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missin In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68817966.
nvd
CVE-2021-0557P3HIGHCVSS 8.8v11.0vAndroid-112021-06-22
CVE-2021-0557 [HIGH] CWE-190 CVE-2021-0557: In setRange of ABuffer.cpp, there is a possible out of bounds write due to an integer overflow. This In setRange of ABuffer.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179046129
nvd
CVE-2021-0473P3HIGHCVSS 8.8v8.1v9.0+3 more2021-06-11
CVE-2021-0473 [HIGH] CWE-908 CVE-2021-0473: In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. Thi In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-179687208
nvd
Google Android vulnerabilities | cvebase