Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 228 of 339
CVE-2022-27823P4HIGHCVSS 7.1v10.0v11.0+1 more2022-04-11
CVE-2022-27823 [HIGH] CWE-125 CVE-2022-27823: Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SM
Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
nvd
CVE-2022-27825P4HIGHCVSS 7.1v10.0v11.0+1 more2022-04-11
CVE-2022-27825 [HIGH] CWE-125 CVE-2022-27825: Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Ap
Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
nvd
CVE-2016-2445P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2445 [HIGH] CWE-264 CVE-2016-2445: The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27253079.
nvd
CVE-2016-2441P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2441 [HIGH] CWE-264 CVE-2016-2441: The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attacke
The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26354602.
nvd
CVE-2016-2446P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2446 [HIGH] CWE-264 CVE-2016-2446: The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27441354.
nvd
CVE-2020-10840P4HIGHCVSS 7.1v9.0v10.02020-03-24
CVE-2020-10840 [HIGH] CWE-401 CVE-2020-10840: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) sof
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is a kernel pointer leak in the vipx driver. The Samsung ID is SVE-2019-16293 (February 2020).
nvd
CVE-2016-2443P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2443 [HIGH] CWE-264 CVE-2016-2443: The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows at
The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525.
nvd
CVE-2016-2442P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2442 [HIGH] CWE-264 CVE-2016-2442: The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attacke
The Qualcomm buspm driver in Android before 2016-05-01 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 26494907.
nvd
CVE-2016-2444P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2444 [HIGH] CWE-264 CVE-2016-2444: The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain pri
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27208332.
nvd
CVE-2016-2456P4HIGHCVSS 7.0≤ 6.0.12016-05-09
CVE-2016-2456 [HIGH] CWE-264 CVE-2016-2456: The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to ga
The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.
nvd
CVE-2016-3886P4MEDIUMCVSS 6.8v7.02016-09-11
CVE-2016-3886 [MEDIUM] CWE-264 CVE-2016-3886: systemui/statusbar/phone/QuickStatusBarHeader.java in the System UI Tuner in Android 7.0 before 2016
systemui/statusbar/phone/QuickStatusBarHeader.java in the System UI Tuner in Android 7.0 before 2016-09-01 does not prevent tuner changes on the lockscreen, which allows physically proximate attackers to gain privileges by modifying a setting, aka internal bug 30107438.
nvd
CVE-2020-10839P4MEDIUMCVSS 6.8v8.0v8.1+2 more2020-03-24
CVE-2020-10839 [MEDIUM] CVE-2020-10839: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attacke
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).
nvd
CVE-2022-20073P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-04-11
CVE-2022-20073 [MEDIUM] CWE-191 CVE-2022-20073: In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could l
In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160841; Issue ID: ALPS06160841.
nvd
CVE-2022-26468P4MEDIUMCVSS 6.6v11.0v12.02022-09-06
CVE-2022-26468 [MEDIUM] CWE-787 CVE-2022-26468: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07168125; Issue ID: ALPS07168125.
nvd
CVE-2022-20059P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20059 [MEDIUM] CWE-787 CVE-2022-20059: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160781.
nvd
CVE-2022-20056P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20056 [MEDIUM] CWE-787 CVE-2022-20056: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160820.
nvd
CVE-2022-20058P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20058 [MEDIUM] CWE-787 CVE-2022-20058: In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This coul
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160485.
nvd
CVE-2022-20074P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-04-11
CVE-2022-20074 [MEDIUM] CWE-125 CVE-2022-20074: In preloader (partition), there is a possible out of bounds write due to a missing bounds check. Thi
In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06183301; Issue ID: ALPS06183301.
nvd
CVE-2016-11034P4MEDIUMCVSS 6.5v5.0v5.1+1 more2020-04-07
CVE-2016-11034 [MEDIUM] CWE-755 CVE-2016-11034: An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode fu
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).
nvd
CVE-2022-20021P4MEDIUMCVSS 6.5v10.0v11.02022-01-04
CVE-2022-20021 [MEDIUM] CVE-2022-20021: In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the re
In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198513; Issue ID: ALPS06198513.
nvd