Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 275 of 339
CVE-2023-48347P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48347 [MEDIUM] CWE-125 CVE-2023-48347: In video decoder, there is a possible out of bounds read due to improper input validation. This coul
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48459P4MEDIUMCVSS 5.5v11.0v12.02023-11-01
CVE-2022-48459 [MEDIUM] CWE-20 CVE-2022-48459: In TeleService, there is a possible system crash due to improper input validation. This could lead t
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48458P4MEDIUMCVSS 5.5v11.0v12.02023-11-01
CVE-2022-48458 [MEDIUM] CWE-20 CVE-2022-48458: In TeleService, there is a possible system crash due to improper input validation. This could lead t
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48454P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2022-48454 [MEDIUM] CWE-787 CVE-2022-48454: In wifi service, there is a possible out of bounds write due to a missing bounds check. This could l
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48457P4MEDIUMCVSS 5.5v11.0v12.02023-11-01
CVE-2022-48457 [MEDIUM] CWE-20 CVE-2022-48457: In TeleService, there is a possible system crash due to improper input validation. This could lead t
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48455P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2022-48455 [MEDIUM] CWE-787 CVE-2022-48455: In wifi service, there is a possible out of bounds write due to a missing bounds check. This could l
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-21365P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21365 [MEDIUM] CVE-2023-21365: In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local den
In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-38554P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-04
CVE-2023-38554 [MEDIUM] CWE-787 CVE-2023-38554: In wcn bsp driver, there is a possible out of bounds write due to a missing bounds check.This could
In wcn bsp driver, there is a possible out of bounds write due to a missing bounds check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-20826P4MEDIUMCVSS 5.5v12.0v13.02023-09-04
CVE-2023-20826 [MEDIUM] CWE-862 CVE-2023-20826: In cta, there is a possible information disclosure due to a missing permission check. This could lea
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550.
nvd
CVE-2025-48542P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48542 [MEDIUM] CWE-400 CVE-2025-48542: In multiple functions of AccountManagerService.java, there is a possible permanent denial of service
In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-52352P4MEDIUMCVSS 5.5v13.0v14.02024-04-08
CVE-2023-52352 [MEDIUM] CWE-862 CVE-2023-52352: In Network Adapter Service, there is a possible missing permission check. This could lead to local d
In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-40640P4MEDIUMCVSS 5.5v10.02023-10-08
CVE-2023-40640 [MEDIUM] CWE-862 CVE-2023-40640: In SoundRecorder service, there is a possible missing permission check. This could lead to local inf
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2024-32912P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-32912 [MEDIUM] CWE-400 CVE-2024-32912: there is a possible persistent Denial of Service due to test/debugging code left in a production bui
there is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of service of impaired use of the device with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-0850P4MEDIUMCVSS 5.3v7.0v7.1.1+1 more2017-11-16
CVE-2017-0850 [MEDIUM] CWE-200 CVE-2017-0850: An information disclosure vulnerability in the Android media framework (libstagefright). Product: An
An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-64836941.
nvd
CVE-2017-13295P4MEDIUMCVSS 5.3v6.0v6.0.1+5 more2018-04-04
CVE-2017-13295 [MEDIUM] CWE-20 CVE-2017-13295: A denial of service vulnerability in the Android framework (package installer). Product: Android. Ve
A denial of service vulnerability in the Android framework (package installer). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62537081.
nvd
CVE-2017-18659P4MEDIUMCVSS 5.3v4.4v5.0+6 more2020-04-07
CVE-2017-18659 [MEDIUM] CWE-755 CVE-2017-18659: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) softw
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can crash system processes via a broadcast to AdaptiveDisplayColorService. The Samsung ID is SVE-2017-8290 (July 2017).
nvd
CVE-2020-11607P4MEDIUMCVSS 5.3v9.0v10.02020-04-08
CVE-2020-11607 [MEDIUM] CVE-2020-11607: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Notification exp
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Notification exposure occurs in Lockdown mode because of the Edge Lighting application. The Samsung ID is SVE-2020-16680 (April 2020).
nvd
CVE-2017-0851P4MEDIUMCVSS 5.3v5.0v5.0.2+7 more2017-11-16
CVE-2017-0851 [MEDIUM] CWE-200 CVE-2017-0851: An information disclosure vulnerability in the Android media framework (libhevc). Product: Android.
An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-35430570.
nvd
CVE-2017-0848P4MEDIUMCVSS 5.3v5.0.2v5.1.1+6 more2017-11-16
CVE-2017-0848 [MEDIUM] CWE-200 CVE-2017-0848: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64477217.
nvd
CVE-2017-0849P4MEDIUMCVSS 5.3v6.0v6.0.1+4 more2017-11-16
CVE-2017-0849 [MEDIUM] CWE-200 CVE-2017-0849: An information disclosure vulnerability in the Android media framework (libavc). Product: Android. V
An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62688399.
nvd