cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 228 of 339
CVE-2022-27823P4HIGHCVSS 7.1v10.0v11.0+1 more2022-04-11
CVE-2022-27823 [HIGH] CWE-125 CVE-2022-27823: Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SM Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
nvd
CVE-2022-27825P4HIGHCVSS 7.1v10.0v11.0+1 more2022-04-11
CVE-2022-27825 [HIGH] CWE-125 CVE-2022-27825: Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Ap Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
nvd
CVE-2016-2445P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2445 [HIGH] CWE-264 CVE-2016-2445: The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27253079.
nvd
CVE-2016-2441P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2441 [HIGH] CWE-264 CVE-2016-2441: The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attacke The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26354602.
nvd
CVE-2016-2446P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2446 [HIGH] CWE-264 CVE-2016-2446: The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27441354.
nvd
CVE-2020-10840P4HIGHCVSS 7.1v9.0v10.02020-03-24
CVE-2020-10840 [HIGH] CWE-401 CVE-2020-10840: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) sof An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is a kernel pointer leak in the vipx driver. The Samsung ID is SVE-2019-16293 (February 2020).
nvd
CVE-2016-2443P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2443 [HIGH] CWE-264 CVE-2016-2443: The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows at The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525.
nvd
CVE-2016-2442P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2442 [HIGH] CWE-264 CVE-2016-2442: The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attacke The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26494907.
nvd
CVE-2016-2444P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2444 [HIGH] CWE-264 CVE-2016-2444: The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27208332.
nvd
CVE-2016-2456P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2456 [HIGH] CWE-264 CVE-2016-2456: The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to ga The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.
nvd
CVE-2016-3886P4MEDIUMCVSS 6.8v7.02016-09-11
CVE-2016-3886 [MEDIUM] CWE-264 CVE-2016-3886: systemui/statusbar/phone/QuickStatusBarHeader.java in the System UI Tuner in Android 7.0 before 2016 systemui/statusbar/phone/QuickStatusBarHeader.java in the System UI Tuner in Android 7.0 before 2016-09-01 does not prevent tuner changes on the lockscreen, which allows physically proximate attackers to gain privileges by modifying a setting, aka internal bug 30107438.
nvd
CVE-2020-10839P4MEDIUMCVSS 6.8v8.0v8.1+2 more2020-03-24
CVE-2020-10839 [MEDIUM] CVE-2020-10839: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attacke An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).
nvd
CVE-2022-20073P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-04-11
CVE-2022-20073 [MEDIUM] CWE-191 CVE-2022-20073: In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could l In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160841; Issue ID: ALPS06160841.
nvd
CVE-2022-26468P4MEDIUMCVSS 6.6v11.0v12.02022-09-06
CVE-2022-26468 [MEDIUM] CWE-787 CVE-2022-26468: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07168125; Issue ID: ALPS07168125.
nvd
CVE-2022-20059P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20059 [MEDIUM] CWE-787 CVE-2022-20059: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160781.
nvd
CVE-2022-20056P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20056 [MEDIUM] CWE-787 CVE-2022-20056: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160820.
nvd
CVE-2022-20058P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20058 [MEDIUM] CWE-787 CVE-2022-20058: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160485.
nvd
CVE-2022-20074P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-04-11
CVE-2022-20074 [MEDIUM] CWE-125 CVE-2022-20074: In preloader (partition), there is a possible out of bounds write due to a missing bounds check. Thi In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06183301; Issue ID: ALPS06183301.
nvd
CVE-2016-11034P4MEDIUMCVSS 6.5v5.0v5.1+1 more2020-04-07
CVE-2016-11034 [MEDIUM] CWE-755 CVE-2016-11034: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode fu An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).
nvd
CVE-2022-20021P4MEDIUMCVSS 6.5v10.0v11.02022-01-04
CVE-2022-20021 [MEDIUM] CVE-2022-20021: In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the re In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198513; Issue ID: ALPS06198513.
nvd
Google Android vulnerabilities | cvebase