cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 252 of 339
CVE-2015-8956P4MEDIUMCVSS 6.1≤ 7.02016-10-10
CVE-2015-8956 [MEDIUM] CWE-476 CVE-2015-8956: The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows l The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket.
nvd
CVE-2016-0813P4MEDIUMCVSS 6.1v5.1v5.1.0+3 more2016-02-07
CVE-2016-0813 [MEDIUM] CWE-264 CVE-2016-0813: packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before 2016-02-01 does not properly check for device provisioning, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors
nvd
CVE-2016-0832P4MEDIUMCVSS 6.1v5.0v5.0.1+6 more2016-03-12
CVE-2016-0832 [MEDIUM] CWE-254 CVE-2016-0832: Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate at Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.
nvdosv
CVE-2017-0641P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-06-14
CVE-2017-0641 [MEDIUM] CWE-665 CVE-2017-0641: A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.
nvd
CVE-2017-0420P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-02-08
CVE-2017-0420 [MEDIUM] CWE-200 CVE-2017-0420: An information disclosure vulnerability in AOSP Mail could enable a local malicious application to b An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2,
nvd
CVE-2017-0413P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-02-08
CVE-2017-0413 [MEDIUM] CWE-200 CVE-2017-0413: An information disclosure vulnerability in AOSP Messaging could enable a local malicious application An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0
nvd
CVE-2016-6682P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6682 [MEDIUM] CWE-200 CVE-2016-6682: drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 30152501 and Qualcomm internal bug CR 1049615.
nvd
CVE-2016-6681P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6681 [MEDIUM] CWE-200 CVE-2016-6681: drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 30152182 and Qualcomm internal bug CR 1049521.
nvd
CVE-2017-0421P4MEDIUMCVSS 5.5v5.0v5.0.1+9 more2017-02-08
CVE-2017-0421 [MEDIUM] CWE-200 CVE-2017-0421: An information disclosure vulnerability in the Framework APIs could enable a local malicious applica An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 5.0.
nvd
CVE-2017-0448P4MEDIUMCVSS 5.5≤ 7.1.12017-02-08
CVE-2017-0448 [MEDIUM] CWE-200 CVE-2017-0448: An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious ap An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-32721029. References: N-CVE
nvd
CVE-2014-9900P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9900 [MEDIUM] CWE-200 CVE-2014-9900: The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Andro The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.
nvd
CVE-2019-2135P4MEDIUMCVSS 5.5v7.0v7.1.1+5 more2019-08-20
CVE-2019-2135 [MEDIUM] CWE-125 CVE-2019-2135: In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missi In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
CVE-2016-3893P4MEDIUMCVSS 5.5≤ 7.02016-09-11
CVE-2016-3893 [MEDIUM] CWE-200 CVE-2016-3893: The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound code The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P devices does not properly copy firmware data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29512527 and Qualcomm internal bug CR856400.
nvd
CVE-2017-0560P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-04-07
CVE-2017-0560 [MEDIUM] CWE-200 CVE-2017-0560: An information disclosure vulnerability in the factory reset process could enable a local malicious An information disclosure vulnerability in the factory reset process could enable a local malicious attacker to access data from the previous owner. This issue is rated as Moderate due to the possibility of bypassing device protection. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-30681079.
nvd
CVE-2016-6722P4MEDIUMCVSS 5.5≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-12-13
CVE-2016-6722 [MEDIUM] CWE-200 CVE-2016-6722: An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4 An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sen
nvd
CVE-2014-9897P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9897 [MEDIUM] CWE-200 CVE-2014-9897: sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm components in Android before 2016-08-05 on Ne sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate certain user-space data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28769856 and Qualcomm internal bug CR563752.
nvd
CVE-2014-9893P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9893 [MEDIUM] CWE-200 CVE-2014-9893: drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm components in Android before 2016-08-05 on Nexu drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not properly determine the size of Gamut LUT data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28747914 and Qualcomm internal bug CR542223.
nvd
CVE-2019-2038P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2019-04-19
CVE-2019-2038 [MEDIUM] CWE-125 CVE-2019-2038: In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing boun In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.
nvd
CVE-2020-0167P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0167 [MEDIUM] CWE-125 CVE-2020-0167: In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. Thi In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-129475100
nvd
CVE-2020-27047P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27047 [MEDIUM] CWE-125 CVE-2020-27047: In ce_t4t_update_binary of ce_t4t.cc, there is a possible out of bounds read due to a missing bounds In ce_t4t_update_binary of ce_t4t.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649298
nvd
Google Android vulnerabilities | cvebase