cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 229 of 339
CVE-2017-0792P4MEDIUMCVSS 6.5v7.1.22017-09-08
CVE-2017-0792 [MEDIUM] CWE-200 CVE-2017-0792: A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.
nvd
CVE-2015-3847P4MEDIUMCVSS 6.4≤ 5.12015-10-06
CVE-2015-3847 [MEDIUM] CWE-264 CVE-2015-3847: Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafte Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.
nvd
CVE-2022-20057P4MEDIUMCVSS 6.5v11.0v12.02022-03-10
CVE-2022-20057 [MEDIUM] CWE-755 CVE-2022-20057: In btif, there is a possible memory corruption due to incorrect error handling. This could lead to l In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALPS06271186.
nvd
CVE-2021-25416P4MEDIUMCVSS 6.5v10.0v11.02021-06-11
CVE-2021-25416 [MEDIUM] CWE-94 CVE-2021-25416: Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 a Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
nvd
CVE-2023-44121P4MEDIUMCVSS 6.3≥ 9.0, ≤ 13.02023-09-27
CVE-2023-44121 [MEDIUM] CWE-926 CVE-2023-44121: The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/ The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action "com.lge.lms.things.notification.ACTION". Additionally, this vulnerabili
nvd
CVE-2016-5341P4MEDIUMCVSS 5.9≤ 7.1.02016-12-06
CVE-2016-5341 [MEDIUM] CWE-284 CVE-2016-5341: The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 31470303 and external bug 211602 (and AndroidID-7225554).
nvd
CVE-2026-0049P4MEDIUMCVSS 6.2v14.0v15.0+8 more2026-04-06
CVE-2026-0049 [MEDIUM] CWE-400 CVE-2026-0049: In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48585P4MEDIUMCVSS 6.2v16.0v162026-03-02
CVE-2025-48585 [MEDIUM] CWE-20 CVE-2025-48585: In multiple functions of ProfilingService.java, there is a possible persistent denial of service due In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48587P4MEDIUMCVSS 6.2v16.0v162026-03-02
CVE-2025-48587 [MEDIUM] CWE-20 CVE-2025-48587: In multiple functions of ProfilingService.java, there is a possible persistent denial of service due In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0015P4MEDIUMCVSS 6.2v14.0v15.0+5 more2026-03-02
CVE-2026-0015 [MEDIUM] CWE-20 CVE-2026-0015: In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0014P4MEDIUMCVSS 6.2v14.0v15.0+5 more2026-03-02
CVE-2026-0014 [MEDIUM] CWE-20 CVE-2026-0014: In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-39429P4MEDIUMCVSS 6.2v12.02024-07-01
CVE-2024-39429 [MEDIUM] CWE-787 CVE-2024-39429: In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2024-39430P4MEDIUMCVSS 6.2v12.02024-07-01
CVE-2024-39430 [MEDIUM] CWE-787 CVE-2024-39430: In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-22268P4MEDIUMCVSS 6.1v9.0v10.0+2 more2022-01-10
CVE-2022-22268 [MEDIUM] CWE-285 CVE-2022-22268: Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate a Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
nvd
CVE-2022-23728P4MEDIUMCVSS 6.1fixed in 11.02022-01-21
CVE-2022-23728 [MEDIUM] CWE-684 CVE-2022-23728: Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is L Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.
nvd
CVE-2025-48554P4MEDIUMCVSS 6.1v13.0v14.0+6 more2025-09-04
CVE-2025-48554 [MEDIUM] CWE-693 CVE-2025-48554: In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial o In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-32916P4MEDIUMCVSS 5.9vAndroid kernel2024-06-13
CVE-2024-32916 [MEDIUM] CWE-665 CVE-2024-32916: In fvp_freq_histogram_init of fvp.c, there is a possible Information Disclosure due to uninitialized In fvp_freq_histogram_init of fvp.c, there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0470P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-12-14
CVE-2020-0470 [MEDIUM] CWE-787 CVE-2020-0470: In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffe In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-166268541
nvd
CVE-2020-0385P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-09-17
CVE-2020-0385 [MEDIUM] CWE-787 CVE-2020-0385: In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds chec In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Andro
nvd
CVE-2020-0384P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-09-17
CVE-2020-0384 [MEDIUM] CWE-787 CVE-2020-0384: In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check In Parse_art of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Androi
nvd
Google Android vulnerabilities | cvebase