cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 267 of 339
CVE-2017-0398P4MEDIUMCVSS 5.5v4.4.4v5.1.1+4 more2017-01-13
CVE-2017-0398 [MEDIUM] CWE-200 CVE-2017-0398: An information disclosure vulnerability in Audioserver could enable a local malicious application to An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android IDs: A-32438594, A-326356
nvd
CVE-2016-6753P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6753 [MEDIUM] CWE-200 CVE-2016-6753: An information disclosure vulnerability in kernel components, including the process-grouping subsyst An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Androi
nvd
CVE-2016-0831P4MEDIUMCVSS 5.5v5.0v5.0.1+6 more2016-03-12
CVE-2016-0831 [MEDIUM] CWE-200 CVE-2016-0831: The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in A The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25778215.
nvdosv
CVE-2017-0401P4MEDIUMCVSS 5.5≥ 4.0, ≤ 4.4.4≥ 5.0, ≤ 5.0.2+4 more2017-01-12
CVE-2017-0401 [MEDIUM] CWE-200 CVE-2017-0401: An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.
nvd
CVE-2017-0399P4MEDIUMCVSS 5.5≥ 4.0, ≤ 4.4.4≥ 5.0, ≤ 5.0.2+4 more2017-01-12
CVE-2017-0399 [MEDIUM] CWE-200 CVE-2017-0399: An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.
nvd
CVE-2014-9898P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9898 [MEDIUM] CWE-200 CVE-2014-9898: arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 o arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate input parameters, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28814690 and Qualcomm internal bug CR554575.
nvd
CVE-2014-9896P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9896 [MEDIUM] CWE-200 CVE-2014-9896: drivers/char/adsprpc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (201 drivers/char/adsprpc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate parameters and return values, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28767593 and Qualcomm internal bug CR551795.
nvd
CVE-2014-9899P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9899 [MEDIUM] CWE-200 CVE-2014-9899: drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devi drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices omits certain minimum calculations before copying data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28803909 and Qualcomm internal bug CR547910.
nvd
CVE-2017-0639P4MEDIUMCVSS 5.5v5.0.2v5.1.1+5 more2017-06-14
CVE-2017-0639 [MEDIUM] CWE-200 CVE-2017-0639: An information disclosure vulnerability in Bluetooth component could enable a local malicious applic An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.
nvd
CVE-2017-0646P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-06-14
CVE-2017-0646 [MEDIUM] CWE-200 CVE-2017-0646: An information disclosure vulnerability in Bluetooth component could enable a local malicious applic An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33899337.
nvd
CVE-2017-0645P4MEDIUMCVSS 5.5v6.0.1v7.0+2 more2017-06-14
CVE-2017-0645 [MEDIUM] CWE-200 CVE-2017-0645: An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to a An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35385327.
nvd
CVE-2016-3883P4MEDIUMCVSS 5.5v4.0v4.0.1+21 more2016-09-11
CVE-2016-3883 [MEDIUM] CWE-284 CVE-2016-3883: internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not properly construct warnings about premium SMS messages, which allows attackers to spoof the premium-payment confirmation dialog via a crafted application, aka internal bug 2855
nvd
CVE-2016-3884P4MEDIUMCVSS 5.5v6.0v6.0.1+1 more2016-09-11
CVE-2016-3884 [MEDIUM] CWE-284 CVE-2016-3884: server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6 server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.
nvd
CVE-2022-20494P4MEDIUMCVSS 5.5v10.0v11.0+4 more2023-01-26
CVE-2022-20494 [MEDIUM] CWE-770 CVE-2022-20494: In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exh In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-24379420
nvd
CVE-2016-3906P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-3906 [MEDIUM] CWE-200 CVE-2016-3906: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2017-0598P4MEDIUMCVSS 5.5v4.0v4.0.1+27 more2017-05-12
CVE-2017-0598 [MEDIUM] CWE-200 CVE-2017-0598: An information disclosure vulnerability in the Framework APIs could enable a local malicious applica An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.
nvd
CVE-2016-6698P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6698 [MEDIUM] CWE-200 CVE-2016-6698: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-2460P4MEDIUMCVSS 5.5v4.0v4.0.1+18 more2016-05-09
CVE-2016-2460 [MEDIUM] CWE-200 CVE-2016-2460: mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016 mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27555981.
nvd
CVE-2016-6750P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6750 [MEDIUM] CWE-200 CVE-2016-6750: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-2459P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-05-09
CVE-2016-2459 [MEDIUM] CWE-200 CVE-2016-2459: mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016 mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27556038.
nvd
Google Android vulnerabilities | cvebase