Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 208 of 339
CVE-2025-20636P4MEDIUMCVSS 6.7v12.0v13.0+2 more2025-02-03
CVE-2025-20636 [MEDIUM] CWE-787 CVE-2025-20636: In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to
In secmem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09403554; Issue ID: MSV-2431.
nvd
CVE-2023-20737P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20737 [MEDIUM] CWE-667 CVE-2023-20737: In vcu, there is a possible use after free due to improper locking. This could lead to local escalat
In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645167.
nvd
CVE-2023-20733P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20733 [MEDIUM] CWE-667 CVE-2023-20733: In vcu, there is a possible use after free due to improper locking. This could lead to local escalat
In vcu, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645149.
nvd
CVE-2018-9507P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9507 [MEDIUM] CWE-125 CVE-2018-9507: In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect
In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.
nvd
CVE-2018-9505P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9505 [MEDIUM] CWE-125 CVE-2018-9505: In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds ch
In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-
nvd
CVE-2019-1996P4MEDIUMCVSS 6.5v8.0v8.1+1 more2019-02-28
CVE-2019-1996 [MEDIUM] CWE-125 CVE-2019-1996: In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-11
nvd
CVE-2020-10844P4MEDIUMCVSS 6.5v8.0v8.1+2 more2020-03-24
CVE-2020-10844 [MEDIUM] CWE-125 CVE-2020-10844: An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There i
An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).
nvd
CVE-2019-2227P4MEDIUMCVSS 6.5v9.0v10.0+1 more2019-12-06
CVE-2019-2227 [MEDIUM] CWE-125 CVE-2019-2227: In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This coul
In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-140768453
nvd
CVE-2022-20447P4MEDIUMCVSS 6.5v13.0vAndroid-132022-11-08
CVE-2022-20447 [MEDIUM] CWE-416 CVE-2022-20447: In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This
In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233604485
nvd
CVE-2022-20010P4MEDIUMCVSS 6.5v12.0v12.1+1 more2022-05-10
CVE-2022-20010 [MEDIUM] CWE-125 CVE-2022-20010: In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213519176
nvd
CVE-2022-20468P4MEDIUMCVSS 6.5v10.0v11.0+3 more2022-12-13
CVE-2022-20468 [MEDIUM] CWE-125 CVE-2022-20468: In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bound
In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13An
nvd
CVE-2023-20802P4MEDIUMCVSS 6.5v12.0v13.02023-08-07
CVE-2023-20802 [MEDIUM] CWE-787 CVE-2023-20802: In imgsys, there is a possible memory corruption due to improper input validation. This could lead t
In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420976.
nvd
CVE-2023-20803P4MEDIUMCVSS 6.5v12.0v13.02023-08-07
CVE-2023-20803 [MEDIUM] CWE-787 CVE-2023-20803: In imgsys, there is a possible memory corruption due to improper input validation. This could lead t
In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374.
nvd
CVE-2025-20653P4MEDIUMCVSS 6.5v13.0v14.0+1 more2025-03-03
CVE-2025-20653 [MEDIUM] CWE-190 CVE-2025-20653: In da, there is a possible out of bounds read due to an integer overflow. This could lead to local i
In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291064; Issue ID: MSV-2046.
nvd
CVE-2020-0305P4MEDIUMCVSS 6.4v10.0vAndroid-102020-07-17
CVE-2020-0305 [MEDIUM] CWE-362 CVE-2020-0305: In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could le
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153467744
nvd
CVE-2022-21789P4MEDIUMCVSS 6.4v11.0v12.02022-08-01
CVE-2022-21789 [MEDIUM] CWE-362 CVE-2022-21789: In audio ipi, there is a possible memory corruption due to a race condition. This could lead to loca
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101.
nvd
CVE-2022-32642P4MEDIUMCVSS 6.4v12.02023-02-06
CVE-2022-32642 [MEDIUM] CWE-662 CVE-2022-32642: In ccd, there is a possible memory corruption due to a race condition. This could lead to local esca
In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326547; Issue ID: ALPS07326547.
nvd
CVE-2019-9375P4MEDIUMCVSS 6.4v10.0vAndroid-102019-09-27
CVE-2019-9375 [MEDIUM] CWE-362 CVE-2019-9375: In hostapd, there is a possible out of bounds write due to a race condition. This could lead to loca
In hostapd, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-129344244
nvd
CVE-2020-0045P4MEDIUMCVSS 6.4v10.0vAndroid-102020-03-10
CVE-2020-0045 [MEDIUM] CWE-362 CVE-2020-0045: In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race cond
In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141243101
nvd
CVE-2020-0358P4MEDIUMCVSS 6.4v11.0vAndroid-112020-09-17
CVE-2020-0358 [MEDIUM] CWE-367 CVE-2020-0358: In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to lo
In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150227563
nvd