cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 265 of 339
CVE-2026-20415P4MEDIUMCVSS 5.5v15.02026-02-02
CVE-2026-20415 [MEDIUM] CWE-415 CVE-2026-20415: In imgsys, there is a possible memory corruption due to improper locking. This could lead to local d In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363254; Issue ID: MSV-5617.
nvd
CVE-2016-0825P4MEDIUMCVSS 5.3v6.0.12016-03-12
CVE-2016-0825 [MEDIUM] CWE-200 CVE-2016-0825: The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensi The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 20860039.
nvdosv
CVE-2017-18658P4MEDIUMCVSS 5.3v6.02020-04-07
CVE-2017-18658 [MEDIUM] CWE-476 CVE-2017-18658: An issue was discovered on Samsung mobile devices with M(6.0) software. The multiwindow_facade API a An issue was discovered on Samsung mobile devices with M(6.0) software. The multiwindow_facade API allows attackers to cause a NullPointerException and system halt via an attempted screen touch of a non-existing display. The Samsung ID is SVE-2017-9383 (August 2017).
nvd
CVE-2017-13294P4MEDIUMCVSS 5.3v6.0v6.0.1+5 more2018-04-04
CVE-2017-13294 [MEDIUM] CWE-200 CVE-2017-13294: A information disclosure vulnerability in the Android framework (aosp email application). Product: A A information disclosure vulnerability in the Android framework (aosp email application). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71814449.
nvd
CVE-2020-15581P4MEDIUMCVSS 5.3v8.0v8.1+2 more2020-07-07
CVE-2020-15581 [MEDIUM] CWE-532 CVE-2020-15581: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The ker An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature allows attackers to discover virtual addresses via vectors involving shared memory. The Samsung ID is SVE-2020-17605 (July 2020).
nvd
CVE-2018-21067P4MEDIUMCVSS 5.3v6.02020-04-08
CVE-2018-21067 [MEDIUM] CWE-200 CVE-2018-21067: An issue was discovered on Samsung mobile devices with M(6.0) software. There is an information disc An issue was discovered on Samsung mobile devices with M(6.0) software. There is an information disclosure in a Trustlet because an address is logged. The Samsung ID is SVE-2018-11600 (July 2018).
nvd
CVE-2017-18687P4MEDIUMCVSS 5.3v4.4v5.0+3 more2020-04-07
CVE-2017-18687 [MEDIUM] CWE-200 CVE-2017-18687: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) softw An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. An attacker can obtain the full pathnames of sdcard files by reading the system protected log upon reception of a certain intent. The Samsung ID is SVE-2016-7183 (January 2017).
nvd
CVE-2017-18656P4MEDIUMCVSS 5.3v6.0v7.0+3 more2020-04-07
CVE-2017-18656 [MEDIUM] CWE-125 CVE-2017-18656: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer over-read in a trustlet. The Samsung ID is SVE-2017-8890 (August 2017).
nvd
CVE-2019-20547P4MEDIUMCVSS 5.3v8.0v8.1+1 more2020-03-24
CVE-2019-20547 [MEDIUM] CVE-2019-20547: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Data may leak via An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Data may leak via a Bluetooth debug command. The Samsung ID is SVE-2019-15398 (November 2019).
nvd
CVE-2017-0423P4MEDIUMCVSS 5.3v5.0v5.0.1+9 more2017-02-08
CVE-2017-0423 [MEDIUM] CWE-732 CVE-2017-0423: An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage acc An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586.
nvd
CVE-2019-20555P4MEDIUMCVSS 5.3v7.0v7.1.0+2 more2020-03-24
CVE-2019-20555 [MEDIUM] CWE-862 CVE-2019-20555: An issue was discovered on Samsung mobile devices with N(7.x) software. The Gallery app allows attac An issue was discovered on Samsung mobile devices with N(7.x) software. The Gallery app allows attackers to view all pictures of a locked device. The Samsung ID is SVE-2019-15189 (October 2019).
nvd
CVE-2025-20655P4MEDIUMCVSS 5.3v12.0v14.02025-04-07
CVE-2025-20655 [MEDIUM] CWE-125 CVE-2025-20655: In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04427687; Issue ID: MSV-3183.
nvd
CVE-2015-6632P4MEDIUMCVSS 5.0≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6632 [MEDIUM] CWE-200 CVE-2015-6632: libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to o libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24346430.
nvd
CVE-2015-6626P4MEDIUMCVSS 5.0≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6626 [MEDIUM] CWE-200 CVE-2015-6626: libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to o libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24310423.
nvd
CVE-2021-25338P4MEDIUMCVSS 5.2v10.0v11.02021-03-04
CVE-2021-25338 [MEDIUM] CWE-20 CVE-2021-25338: Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allo Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.
nvd
CVE-2019-9434P4MEDIUMCVSS 4.9v10.0vAndroid-102019-09-27
CVE-2019-9434 [MEDIUM] CWE-125 CVE-2019-9434: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80432895
nvd
CVE-2019-9431P4MEDIUMCVSS 4.9v10.0vAndroid-102019-09-27
CVE-2019-9431 [MEDIUM] CWE-125 CVE-2019-9431: In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to rem In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109755179
nvd
CVE-2024-56188P4MEDIUMCVSS 5.1vAndroid kernel2025-03-10
CVE-2024-56188 [MEDIUM] CWE-476 CVE-2024-56188: there is a possible way to crash the modem due to a missing null check. This could lead to remote de there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43090P4MEDIUMCVSS 5.0v12.0v12.1+7 more2024-11-13
CVE-2024-43090 [MEDIUM] CWE-862 CVE-2024-43090: In multiple locations, there is a possible cross-user image read due to a missing permission check. In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-0019P4MEDIUMCVSS 5.0v12.0v12.1+6 more2024-02-16
CVE-2024-0019 [MEDIUM] CWE-732 CVE-2024-0019: In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
Google Android vulnerabilities | cvebase