cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 215 of 339
CVE-2025-26434P4MEDIUMCVSS 5.5v16.0v162025-09-05
CVE-2025-26434 [MEDIUM] CWE-120 CVE-2025-26434: In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to loca In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26445P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-04
CVE-2025-26445 [MEDIUM] CWE-862 CVE-2025-26445: In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a mis In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36889P4MEDIUMCVSS 5.5vAndroid kernel2025-12-11
CVE-2025-36889 [MEDIUM] CWE-441 CVE-2025-36889: In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused dep In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48608P4MEDIUMCVSS 5.5v16.0v16-qpr22025-12-08
CVE-2025-48608 [MEDIUM] CWE-862 CVE-2025-48608: In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a miss In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20530P4MEDIUMCVSS 5.3v13.0vAndroid-132022-12-16
CVE-2022-20530 [MEDIUM] CWE-451 CVE-2022-20530: In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231585645
nvd
CVE-2023-52533P4MEDIUMCVSS 5.3v12.0v13.0+1 more2024-04-08
CVE-2023-52533 [MEDIUM] CWE-475 CVE-2023-52533: In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This c In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2023-52344P4MEDIUMCVSS 5.3v12.0v13.0+1 more2024-04-08
CVE-2023-52344 [MEDIUM] CWE-476 CVE-2023-52344: In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This c In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2026-0153P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0153 CVE-2026-0153: In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bound In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-2461P4HIGHCVSS 7.0v6.0v6.0.12016-05-09
CVE-2016-2461 [HIGH] CWE-264 CVE-2016-2461: OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bugs 27324690 and 27696681.
nvd
CVE-2016-2462P4HIGHCVSS 7.0v6.0v6.0.12016-05-09
CVE-2016-2462 [HIGH] CWE-264 CVE-2016-2462: OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additiona OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.
nvd
CVE-2019-20531P4HIGHCVSS 7.1v9.02020-03-24
CVE-2019-20531 [HIGH] CWE-125 CVE-2019-20531: An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have an out-of-bounds Read. The Samsung IDs are SVE-2019-15692, SVE-2019-15693 (December 2019).
nvd
CVE-2016-3846P4HIGHCVSS 7.0≤ 6.0.12016-08-05
CVE-2016-3846 [HIGH] CWE-264 CVE-2016-3846: The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allow The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28817378.
nvd
CVE-2016-3848P4HIGHCVSS 7.0≤ 6.0.12016-08-05
CVE-2016-3848 [HIGH] CWE-264 CVE-2016-3848: The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain pri The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28919417.
nvd
CVE-2022-47338P4HIGHCVSS 7.1v10.0v11.02023-04-11
CVE-2022-47338 [HIGH] CWE-668 CVE-2022-47338: In telecom service, there is a missing permission check. This could lead to local denial of service In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2017-8280P4HIGHCVSS 7.0≤ 8.02017-09-21
CVE-2017-8280 [HIGH] CWE-119 CVE-2017-8280: In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan cali In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context switch.
nvd
CVE-2020-10843P4HIGHCVSS 7.0v8.0v8.1+2 more2020-03-24
CVE-2020-10843 [HIGH] CWE-362 CVE-2020-10843: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There are race conditions in the hdcp2 driver. The Samsung ID is SVE-2019-16296 (February 2020).
nvd
CVE-2015-3844P4MEDIUMCVSS 6.8≤ 5.12015-10-01
CVE-2015-3844 [MEDIUM] CWE-264 CVE-2015-3844: The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 LMY48I allows attackers to trigger incorrect process loading via a crafted application, as demonstrated by interfering with use of the Settings application, aka internal bug 21669445.
nvd
CVE-2017-0705P4MEDIUMCVSS 6.8v7.1.22017-07-06
CVE-2017-0705 [MEDIUM] CVE-2017-0705: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.
nvd
CVE-2017-0706P4MEDIUMCVSS 6.8v7.1.22017-07-06
CVE-2017-0706 [MEDIUM] CWE-119 CVE-2017-0706: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532.
nvd
CVE-2019-2233P4MEDIUMCVSS 6.8v10.0vAndroid-102019-11-13
CVE-2019-2233 [MEDIUM] CVE-2019-2233: In getUserCount and getCount of UserSwitcherController.java, there is possible new user creation due In getUserCount and getCount of UserSwitcherController.java, there is possible new user creation due to a logic error. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android
nvd
Google Android vulnerabilities | cvebase