cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 205 of 339
CVE-2016-3856P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2016-3856 [HIGH] CWE-19 CVE-2016-3856: netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.
nvd
CVE-2025-22407P4MEDIUMCVSS 5.5v15.0v152025-08-26
CVE-2025-22407 [MEDIUM] CWE-416 CVE-2025-22407: In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2011-1149P4HIGHCVSS 7.2≤ 2.2.2v1.5+4 more2011-04-21
CVE-2011-1149 [HIGH] CWE-264 CVE-2011-1149: Android before 2.3 does not properly restrict access to the system property space, which allows loca Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK.
nvd
CVE-2026-0127P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0127 CVE-2026-0127: In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bound In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication processor crash with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3890P4HIGHCVSS 7.0v4.0v4.0.1+20 more2016-09-11
CVE-2016-3890 [HIGH] CWE-264 CVE-2016-3890: The Java Debug Wire Protocol (JDWP) implementation in adb/sockets.cpp in Android 4.x before 4.4.4, 5 The Java Debug Wire Protocol (JDWP) implementation in adb/sockets.cpp in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 mishandles socket close operations, which allows attackers to gain privileges via a crafted application, aka internal bug 28347842.
nvd
CVE-2016-0822P4HIGHCVSS 7.0v6.0.12016-03-12
CVE-2016-0822 [HIGH] CWE-264 CVE-2016-0822: The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application that leverages conn_launcher access, aka internal bug 25873324.
nvd
CVE-2022-25821P4HIGHCVSS 7.1v10.0v11.0+1 more2022-03-10
CVE-2022-25821 [HIGH] CWE-125 CVE-2022-25821: Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB re Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
nvd
CVE-2017-13183P4HIGHCVSS 7.0v8.12018-01-12
CVE-2017-13183 [HIGH] CWE-362 CVE-2017-13183: In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interac
nvd
CVE-2020-0256P4MEDIUMCVSS 6.8v8.0v8.1+3 more2020-08-11
CVE-2020-0256 [MEDIUM] CWE-787 CVE-2020-0256: In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds che In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Androi
nvd
CVE-2016-3875P4MEDIUMCVSS 6.8v6.0v6.0.12016-09-11
CVE-2016-3875 [MEDIUM] CWE-264 CVE-2016-3875: server/wm/WindowManagerService.java in Android 6.x before 2016-09-01 does not enforce the DISALLOW_S server/wm/WindowManagerService.java in Android 6.x before 2016-09-01 does not enforce the DISALLOW_SAFE_BOOT setting, which allows physically proximate attackers to bypass intended access restrictions and boot to safe mode via unspecified vectors, aka internal bug 26251884.
nvd
CVE-2020-25280P4MEDIUMCVSS 6.8v10.02020-09-11
CVE-2020-25280 [MEDIUM] CVE-2020-25280: An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) softwa An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated attackers can execute LTE/5G commands by sending a debugging command over USB. The Samsung ID is SVE-2020-16979 (September 2020).
nvd
CVE-2022-20125P4MEDIUMCVSS 6.8v10.0v11.0+3 more2022-06-15
CVE-2022-20125 [MEDIUM] CVE-2022-20125: In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This In GBoard, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to local escalation of privilege if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2021-0703P4MEDIUMCVSS 6.8v11.0vAndroid-112021-10-22
CVE-2021-0703 [MEDIUM] CWE-416 CVE-2021-0703: In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-18456
nvd
CVE-2012-6702P4MEDIUMCVSS 5.9v4.4.4v5.0.2+3 more2016-06-16
CVE-2012-6702 [MEDIUM] CWE-310 CVE-2012-6702: Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
nvd
CVE-2022-20034P4MEDIUMCVSS 6.8v11.02022-02-09
CVE-2022-20034 [MEDIUM] CWE-295 CVE-2022-20034: In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate vali In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160
nvd
CVE-2019-2199P4MEDIUMCVSS 6.7v10.0vAndroid-102019-11-13
CVE-2019-2199 [MEDIUM] CVE-2019-2199: In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. Th In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-138650665
nvd
CVE-2019-9384P4MEDIUMCVSS 6.7v10.0vAndroid-102019-09-27
CVE-2019-9384 [MEDIUM] CVE-2019-9384: In LockPatternUtils, there is a possible escalation of privilege due to an improper permissions chec In LockPatternUtils, there is a possible escalation of privilege due to an improper permissions check. This could lead to local bypass of the Lockguard with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120568007
nvd
CVE-2018-9508P4MEDIUMCVSS 6.5v7.0v7.1.1+3 more2018-10-02
CVE-2018-9508 [MEDIUM] CWE-125 CVE-2018-9508: In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2
nvd
CVE-2020-0122P4MEDIUMCVSS 6.7v8.0v8.1+6 more2020-07-17
CVE-2020-0122 [MEDIUM] CWE-276 CVE-2020-0122: In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in And In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android
nvd
CVE-2019-9266P4MEDIUMCVSS 6.7v10.0vAndroid-102019-09-27
CVE-2019-9266 [MEDIUM] CWE-787 CVE-2019-9266: In sensorservice, there is a possible out of bounds write due to a missing bounds check. This could In sensorservice, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-119501435
nvd
Google Android vulnerabilities | cvebase