Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 239 of 339
CVE-2016-3889P4MEDIUMCVSS 6.8v6.0v6.0.1+1 more2016-09-11
CVE-2016-3889 [MEDIUM] CWE-264 CVE-2016-3889: Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to byp
Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism by accessing (1) an external tile from a system application, (2) the help feature, or (3) the Settings application during a pre-setup stage, aka internal bug 29194585.
nvd
CVE-2021-27901P4MEDIUMCVSS 6.8v11.02021-03-02
CVE-2021-27901 [MEDIUM] CVE-2021-27901: An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint
An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because local high beam mode (LHBM) does not function properly during bright illumination. The LG ID is LVE-SMP-210001 (March 2021).
nvd
CVE-2016-0830P4MEDIUMCVSS 6.5v6.0v6.0.12016-03-12
CVE-2016-0830 [MEDIUM] CWE-119 CVE-2016-0830: btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denia
btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of configuration entries, and consequently exceeding the maximum size of a configuration file, aka internal bug 26071376.
nvdosv
CVE-2015-6643P4MEDIUMCVSS 6.6v5.1.1v6.0+1 more2016-01-06
CVE-2015-6643 [MEDIUM] CWE-264 CVE-2015-6643: Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximat
Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.
nvd
CVE-2017-0880P4MEDIUMCVSS 6.5v7.0v7.1.1+2 more2017-12-06
CVE-2017-0880 [MEDIUM] CVE-2017-0880: A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versio
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID A-65646012.
nvd
CVE-2017-13148P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2017-12-06
CVE-2017-13148 [MEDIUM] CWE-20 CVE-2017-13148: A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versi
A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65717533.
nvd
CVE-2017-0874P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2017-12-06
CVE-2017-0874 [MEDIUM] CWE-20 CVE-2017-0874: A denial of service vulnerability in the Android media framework (libavc). Product: Android. Version
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63315932.
nvd
CVE-2017-0873P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2017-12-06
CVE-2017-0873 [MEDIUM] CWE-20 CVE-2017-0873: A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versi
A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63316255.
nvd
CVE-2017-0783P4MEDIUMCVSS 6.5v4.0v4.0.1+28 more2017-09-14
CVE-2017-0783 [MEDIUM] CWE-200 CVE-2017-0783: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.
nvd
CVE-2018-21092P4MEDIUMCVSS 6.5v6.0v6.0.1+4 more2020-04-08
CVE-2018-21092 [MEDIUM] CWE-20 CVE-2018-21092: An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT comm
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via an NFC tag. The Samsung ID is SVE-2017-10885 (January 2018).
nvd
CVE-2015-6646P4MEDIUMCVSS 6.2v6.02016-01-06
CVE-2015-6646 [MEDIUM] CWE-399 CVE-2015-6646: The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to c
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager, aka internal bug 22300191, a different vulnerability than CVE-2015-7613.
nvd
CVE-2016-2414P4MEDIUMCVSS 6.2v5.0v5.0.1+4 more2016-04-18
CVE-2016-2414 [MEDIUM] CWE-20 CVE-2016-2414: The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 doe
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177.
nvd
CVE-2023-20851P4MEDIUMCVSS 6.3v11.0v13.02023-09-04
CVE-2023-20851 [MEDIUM] CWE-125 CVE-2023-20851: In stc, there is a possible out of bounds read due to a race condition. This could lead to local esc
In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.
nvd
CVE-2017-13290P4MEDIUMCVSS 6.2v6.0v6.0.1+5 more2018-04-04
CVE-2017-13290 [MEDIUM] CWE-125 CVE-2017-13290: In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bo
In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69384124.
nvd
CVE-2025-31712P4MEDIUMCVSS 6.2v13.0v14.0+1 more2025-06-03
CVE-2025-31712 [MEDIUM] CWE-120 CVE-2025-31712: In cplog service, there is a possible out of bounds write due to a missing bounds check. This could
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.
nvd
CVE-2021-25363P4MEDIUMCVSS 6.1v8.1v9.0+2 more2021-04-09
CVE-2021-25363 [MEDIUM] CWE-269 CVE-2021-25363: An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untruste
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.
nvd
CVE-2021-25362P4MEDIUMCVSS 6.1v8.1v9.0+1 more2021-04-09
CVE-2021-25362 [MEDIUM] CWE-269 CVE-2021-25362: An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
nvd
CVE-2015-6614P4MEDIUMCVSS 5.8v5.0v5.12015-11-03
CVE-2015-6614 [MEDIUM] CWE-264 CVE-2015-6614: Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently b
Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulation), via a crafted application, aka internal bug 21900139.
nvd
CVE-2016-5349P4MEDIUMCVSS 5.5≤ 7.1.12017-04-06
CVE-2016-5349 [MEDIUM] CWE-200 CVE-2016-5349: The high level operating systems (HLOS) was not providing sufficient memory address information to e
The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure application's HLOS client. When secure applications inside Qualcomm Secure Execution Environment (QSEE)
nvd
CVE-2020-0014P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-02-13
CVE-2020-0014 [MEDIUM] CWE-1021 CVE-2020-0014: It is possible for a malicious application to construct a TYPE_TOAST window manually and make that w
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520
nvd