cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 238 of 339
CVE-2024-47025P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47025 [MEDIUM] CWE-863 CVE-2024-47025: In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36921P4MEDIUMCVSS 5.5vAndroid kernel2025-12-11
CVE-2025-36921 [MEDIUM] CWE-125 CVE-2025-36921: In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2018-6246P4MEDIUMCVSS 5.3≤ 8.12018-05-10
CVE-2018-6246 [MEDIUM] CWE-200 CVE-2018-6246: In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerabi In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure. This issue is rated as moderate. Android: A-69383916. Reference: N-CVE-2018-6246.
nvd
CVE-2020-12748P4MEDIUMCVSS 5.3v10.02020-05-11
CVE-2020-12748 [MEDIUM] CVE-2020-12748: An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the lo An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and designate a different preferred SIM card. The Samsung ID is SVE-2020-16594 (May 2020).
nvd
CVE-2017-18657P4MEDIUMCVSS 5.3v6.0v7.0+3 more2020-04-07
CVE-2017-18657 [MEDIUM] CWE-754 CVE-2017-18657: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is an arbit An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is an arbitrary write in a trustlet. The Samsung ID is SVE-2017-8893 (August 2017).
nvd
CVE-2022-30716P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-06-07
CVE-2022-30716 [MEDIUM] CWE-280 CVE-2022-30716: Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 a Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.
nvd
CVE-2022-30709P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-06-07
CVE-2022-30709 [MEDIUM] CWE-20 CVE-2022-30709: Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
nvd
CVE-2022-30720P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-06-07
CVE-2022-30720 [MEDIUM] CWE-20 CVE-2022-30720: Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Releas Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
nvd
CVE-2022-30719P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-06-07
CVE-2022-30719 [MEDIUM] CWE-20 CVE-2022-30719: Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Releas Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
nvd
CVE-2022-30721P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-06-07
CVE-2022-30721 [MEDIUM] CWE-20 CVE-2022-30721: Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Releas Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
nvd
CVE-2022-30715P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-06-07
CVE-2022-30715 [MEDIUM] CWE-284 CVE-2022-30715: Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.
nvd
CVE-2022-36861P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-09-09
CVE-2022-36861 [MEDIUM] CWE-269 CVE-2022-36861: Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker t Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.
nvd
CVE-2025-26426P4MEDIUMCVSS 5.1v13.0v14.0+4 more2025-09-04
CVE-2025-26426 [MEDIUM] CWE-20 CVE-2025-26426: In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22425P4MEDIUMCVSS 5.1v13.0v14.0+2 more2025-09-04
CVE-2025-22425 [MEDIUM] CWE-276 CVE-2025-22425: In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input valid In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-48413P4MEDIUMCVSS 4.9vAndroid kernel2023-12-08
CVE-2023-48413 [MEDIUM] CWE-125 CVE-2023-48413: In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds ch In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-48397P4MEDIUMCVSS 4.9vAndroid kernel2023-12-08
CVE-2023-48397 [MEDIUM] CWE-125 CVE-2023-48397: In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds c In Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20102P4MEDIUMCVSS 4.9v13.0v14.02024-10-07
CVE-2024-20102 [MEDIUM] CWE-125 CVE-2024-20102: In wlan driver, there is a possible out of bounds read due to improper input validation. This could In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; Issue ID: MSV-1601.
nvd
CVE-2026-0138P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0138 CVE-2026-0138: In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory c In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0152P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0152 CVE-2026-0152: In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2013-5933P4MEDIUMCVSS 6.9v2.3.72013-09-25
CVE-2013-5933 [MEDIUM] CWE-119 CVE-2013-5933: Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2 Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the /dev/socket/init_runit socket that is inconsistent with a certain length valu
nvd
Google Android vulnerabilities | cvebase