Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 22 of 339
CVE-2016-2506P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-2506 [CRITICAL] CWE-119 CVE-2016-2506: DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5
DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate a certain offset value, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28175045.
nvd
CVE-2026-0097P3HIGHCVSS 8.0v14.0v15.0+8 more2026-06-01
CVE-2026-0097 [HIGH] CWE-693 CVE-2026-0097: In multiple locations, there is a possible way to bypass user interaction when pairing an LE device
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0059P3HIGHCVSS 8.0v14.0v15.0+8 more2026-06-01
CVE-2026-0059 [HIGH] CWE-122 CVE-2026-0059: In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36924P3HIGHCVSS 8.0vAndroid kernel2025-12-11
CVE-2025-36924 [HIGH] CWE-120 CVE-2025-36924: In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write
In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-21044P3CRITICALCVSS 9.8v7.0v7.1.0+3 more2020-04-08
CVE-2018-21044 [CRITICAL] CWE-120 CVE-2018-21044: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) software. The sem Trustlet
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) software. The sem Trustlet has a buffer overflow that leads to arbitrary TEE code execution. The Samsung IDs are SVE-2018-13230, SVE-2018-13231, SVE-2018-13232, SVE-2018-13233 (December 2018).
nvd
CVE-2017-13274P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13274 [CRITICAL] CWE-346 CVE-2017-13274: In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determin
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71360761.
nvd
CVE-2022-30722P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-06-07
CVE-2022-30722 [CRITICAL] CWE-285 CVE-2022-30722: Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows at
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
nvd
CVE-2023-35649P3HIGHCVSS 7.2vAndroid kernel2023-10-11
CVE-2023-35649 [HIGH] CWE-787 CVE-2023-35649: In several functions of Exynos modem files, there is a possible out of bounds write due to a missing
In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-9232P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9232 [HIGH] CWE-125 CVE-2019-9232: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
nvd
CVE-2014-7951P4MEDIUMCVSS 4.6PoCv4.0.42020-02-20
CVE-2014-7951 [MEDIUM] CWE-22 CVE-2014-7951: Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows phys
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar archive headers.
nvd
CVE-2018-9571P3HIGHCVSS 8.8v9.02018-12-07
CVE-2018-9571 [HIGH] CWE-787 CVE-2018-9571: In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound wr
In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116020594.
nvd
CVE-2018-9569P3HIGHCVSS 8.8v9.02018-12-07
CVE-2018-9569 [HIGH] CWE-787 CVE-2018-9569: In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound writ
In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113885537.
nvd
CVE-2021-0967P3HIGHCVSS 8.8v9.0v10.0+3 more2021-12-15
CVE-2021-0967 [HIGH] CWE-787 CVE-2021-0967: In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing b
In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199065614
nvd
CVE-2019-2062P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-2062 [HIGH] CWE-787 CVE-2019-2062: In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead t
In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117660045
nvd
CVE-2019-9256P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-9256 [HIGH] CWE-190 CVE-2019-9256: In libmediaextractor there is a possible out of bounds write due to an integer overflow. This could
In libmediaextractor there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111921829
nvd
CVE-2019-9262P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-9262 [HIGH] CWE-190 CVE-2019-9262: In MPEG4Extractor, there is a possible out of bounds write due to an integer overflow. This could le
In MPEG4Extractor, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111792351
nvd
CVE-2018-9533P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9533 [HIGH] CWE-119 CVE-2018-9533: In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missin
In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112766520
nvd
CVE-2020-0194P3HIGHCVSS 8.8v10.0vAndroid-102020-06-11
CVE-2020-0194 [HIGH] CWE-190 CVE-2020-0194: In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write
In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590
nvd
CVE-2019-9304P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-9304 [HIGH] CWE-190 CVE-2019-9304: In libMpegTPDec, there is a possible out of bounds write due to an integer overflow. This could lead
In libMpegTPDec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112662270
nvd
CVE-2019-2081P3HIGHCVSS 8.8v10.0vAndroid-102019-09-27
CVE-2019-2081 [HIGH] CWE-787 CVE-2019-2081: In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to
In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116473261
nvd