Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 268 of 339
CVE-2016-6721P4MEDIUMCVSS 5.5≥ 6.0, ≤ 6.0.1v7.02016-11-25
CVE-2016-6721 [MEDIUM] CWE-200 CVE-2016-6721: An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 befo
An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-30875060.
nvd
CVE-2016-6718P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6718 [MEDIUM] CWE-200 CVE-2016-6718: An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11
An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to retrieve sensitive information without user interaction. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require
nvd
CVE-2017-0793P4MEDIUMCVSS 5.5≤ 8.02017-09-08
CVE-2017-0793 [MEDIUM] CWE-200 CVE-2017-0793: A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Andr
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.
nvd
CVE-2017-0489P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-03-08
CVE-2017-0489 [MEDIUM] CVE-2017-0489: An elevation of privilege vulnerability in Location Manager could enable a local malicious applicati
An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33091107.
nvd
CVE-2016-2426P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-04-18
CVE-2016-2426 [MEDIUM] CWE-200 CVE-2016-2426: server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x bef
server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 26094635.
nvd
CVE-2016-3908P4MEDIUMCVSS 5.5v6.0v6.0.1+1 more2016-10-10
CVE-2016-3908 [MEDIUM] CWE-264 CVE-2016-3908: The Lock Settings Service in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attacker
The Lock Settings Service in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to remove a device's PIN or password, and consequently gain privileges, via a crafted application, aka internal bug 30003944.
nvd
CVE-2017-11001P4MEDIUMCVSS 5.5≤ 8.02017-09-21
CVE-2017-11001 [MEDIUM] CWE-200 CVE-2017-11001: In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MA
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
nvd
CVE-2016-6748P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6748 [MEDIUM] CWE-200 CVE-2016-6748: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6752P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6752 [MEDIUM] CWE-200 CVE-2016-6752: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6749P4MEDIUMCVSS 5.5≤ 7.1.0v7.02016-11-25
CVE-2016-6749 [MEDIUM] CWE-200 CVE-2016-6749: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-6751P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6751 [MEDIUM] CWE-200 CVE-2016-6751: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2016-3907P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-3907 [MEDIUM] CWE-200 CVE-2016-3907: An information disclosure vulnerability in Qualcomm components including the GPU driver, power drive
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged
nvd
CVE-2019-9464P4MEDIUMCVSS 5.5v10.0vAndroid-102019-12-06
CVE-2019-9464 [MEDIUM] CWE-732 CVE-2019-9464: In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionSer
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could dissolve the trust in the platform's permission system, with no additional execution privileges needed. User interaction is needed for exploitation.Produ
nvd
CVE-2016-2500P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-06-13
CVE-2016-2500 [MEDIUM] CWE-200 CVE-2016-2500: Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does n
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 19285814.
nvd
CVE-2016-2498P4MEDIUMCVSS 5.5v6.0v6.0.12016-06-13
CVE-2016-2498 [MEDIUM] CWE-200 CVE-2016-2498: The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a crafted application, aka internal bug 27777162.
nvd
CVE-2020-0159P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0159 [MEDIUM] CWE-125 CVE-2020-0159: In rw_mfc_writeBlock of rw_mfc.cc, there is a possible out of bounds read due to an incorrect bounds
In rw_mfc_writeBlock of rw_mfc.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140768035
nvd
CVE-2016-5346P4MEDIUMCVSS 5.5fixed in 7.02020-01-08
CVE-2016-5346 [MEDIUM] CWE-200 CVE-2016-5346: An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).
nvd
CVE-2017-0493P4MEDIUMCVSS 5.5v7.0v7.1.0+1 more2017-05-12
CVE-2017-0493 [MEDIUM] CWE-922 CVE-2017-0493: An information disclosure vulnerability in File-Based Encryption could enable a local malicious atta
An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32793550.
nvd
CVE-2020-0443P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-11-10
CVE-2020-0443 [MEDIUM] CWE-755 CVE-2020-0443: In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. Th
In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android I
nvd
CVE-2016-8462P4MEDIUMCVSS 5.5≤ 7.1.02017-01-12
CVE-2016-8462 [MEDIUM] CWE-200 CVE-2016-8462: An information disclosure vulnerability in the bootloader could enable a local attacker to access da
An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: N/A. Android ID: A-32510383.
nvd