Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 203 of 339
CVE-2023-20809P4MEDIUMCVSS 6.7v10.0v11.02023-08-07
CVE-2023-20809 [MEDIUM] CWE-787 CVE-2023-20809: In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03751198; Issue ID: DTV03751198.
nvd
CVE-2023-20808P4MEDIUMCVSS 6.7v11.02023-08-07
CVE-2023-20808 [MEDIUM] CWE-787 CVE-2023-20808: In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to
In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID: DTV03645895.
nvd
CVE-2019-2168P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2168 [MEDIUM] CWE-908 CVE-2019-2168: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118492594
nvd
CVE-2019-2140P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2140 [MEDIUM] CWE-908 CVE-2019-2140: In libxaac, there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac, there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112705708
nvd
CVE-2019-2167P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2167 [MEDIUM] CWE-908 CVE-2019-2167: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118615501
nvd
CVE-2019-2166P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2166 [MEDIUM] CWE-908 CVE-2019-2166: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117661478
nvd
CVE-2019-2169P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2169 [MEDIUM] CWE-908 CVE-2019-2169: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118492282
nvd
CVE-2019-2171P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2171 [MEDIUM] CWE-908 CVE-2019-2171: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113035086
nvd
CVE-2019-2172P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2172 [MEDIUM] CWE-908 CVE-2019-2172: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113035224
nvd
CVE-2019-2170P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-2170 [MEDIUM] CWE-908 CVE-2019-2170: In libxaac there is a possible information disclosure due to uninitialized data. This could lead to
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118615735
nvd
CVE-2024-20140P4MEDIUMCVSS 6.7v12.0v13.0+2 more2025-01-06
CVE-2024-20140 [MEDIUM] CWE-787 CVE-2024-20140: In power, there is a possible out of bounds write due to a missing bounds check. This could lead to
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020.
nvd
CVE-2024-20125P4MEDIUMCVSS 6.7v13.0v14.02024-12-02
CVE-2024-20125 [MEDIUM] CWE-787 CVE-2024-20125: In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained System privileges. User interaction is not needed for exploitation. Patch ID: ALPS09046782; Issue ID: MSV-1728.
nvd
CVE-2023-20619P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-02-06
CVE-2023-20619 [MEDIUM] CWE-667 CVE-2023-20619: In vcu, there is a possible memory corruption due to improper locking. This could lead to local esca
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519159; Issue ID: ALPS07519159.
nvd
CVE-2023-20618P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-02-06
CVE-2023-20618 [MEDIUM] CWE-667 CVE-2023-20618: In vcu, there is a possible memory corruption due to improper locking. This could lead to local esca
In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519184; Issue ID: ALPS07519184.
nvd
CVE-2023-20743P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20743 [MEDIUM] CWE-667 CVE-2023-20743: In vcu, there is a possible out of bounds write due to improper locking. This could lead to local es
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519142.
nvd
CVE-2023-20746P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20746 [MEDIUM] CWE-667 CVE-2023-20746: In vcu, there is a possible out of bounds write due to improper locking. This could lead to local es
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519217.
nvd
CVE-2023-20745P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20745 [MEDIUM] CWE-667 CVE-2023-20745: In vcu, there is a possible out of bounds write due to improper locking. This could lead to local es
In vcu, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07560694.
nvd
CVE-2018-9588P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9588 [MEDIUM] CWE-125 CVE-2018-9588: In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0,
In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploita
nvd
CVE-2018-9594P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9594 [MEDIUM] CWE-125 CVE-2018-9594: In llcp_link_proc_agf_pdu of llcp_link.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0,
In llcp_link_proc_agf_pdu of llcp_link.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation. Andr
nvd
CVE-2021-0632P4MEDIUMCVSS 6.5v8.1v9.0+2 more2021-10-25
CVE-2021-0632 [MEDIUM] CWE-125 CVE-2021-0632: In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lea
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker under certain build conditions with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05560246; Issue ID: ALPS05551383.
nvd