Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 276 of 339
CVE-2017-13297P4MEDIUMCVSS 5.3v6.0v6.0.1+5 more2018-04-04
CVE-2017-13297 [MEDIUM] CWE-200 CVE-2017-13297: A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. V
A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71766721.
nvd
CVE-2017-13296P4MEDIUMCVSS 5.3v6.0v6.0.1+5 more2018-04-04
CVE-2017-13296 [MEDIUM] CWE-200 CVE-2017-13296: A information disclosure vulnerability in the Android media framework (libavc). Product: Android. Ve
A information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897454.
nvd
CVE-2017-13298P4MEDIUMCVSS 5.3v6.0v6.0.1+5 more2018-04-04
CVE-2017-13298 [MEDIUM] CWE-200 CVE-2017-13298: A information disclosure vulnerability in the Android media framework (libhavc). Product: Android. V
A information disclosure vulnerability in the Android media framework (libhavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-72117051.
nvd
CVE-2017-18686P4MEDIUMCVSS 5.3v6.0v7.02020-04-07
CVE-2017-18686 [MEDIUM] CWE-200 CVE-2017-18686: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) software. Contact informati
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) software. Contact information can leak to a log file because of the broadcasting of an unprotected intent. The Samsung ID is SVE-2016-7180 (February 2017).
nvd
CVE-2019-20617P4MEDIUMCVSS 5.3v9.02020-03-24
CVE-2019-20617 [MEDIUM] CVE-2019-20617: An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Folder leaks preview
An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Folder leaks preview data of recent apps. The Samsung ID is SVE-2018-13764 (March 2019).
nvd
CVE-2020-10853P4MEDIUMCVSS 5.3v9.02020-03-24
CVE-2020-10853 [MEDIUM] CVE-2020-10853: An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. T
An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are SVE-2019-16010, SVE-2019-16011, SVE-2019-16012 (January 2020).
nvd
CVE-2019-20593P4MEDIUMCVSS 5.3v7.0v7.1.0+4 more2020-03-24
CVE-2019-20593 [MEDIUM] CWE-552 CVE-2019-20593: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Pri
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).
nvd
CVE-2020-10834P4MEDIUMCVSS 5.3v9.02020-03-24
CVE-2020-10834 [MEDIUM] CVE-2020-10834: An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view notificat
An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view notifications on the lock screen via Routines. The Samsung ID is SVE-2019-15074 (February 2020).
nvd
CVE-2019-20616P4MEDIUMCVSS 5.3v7.0v7.1.0+4 more2020-03-24
CVE-2019-20616 [MEDIUM] CWE-200 CVE-2019-20616: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks a t
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks a thumbnail of Private Mode content. The Samsung ID is SVE-2018-13563 (March 2019).
nvd
CVE-2019-20624P4MEDIUMCVSS 5.3v7.0v7.1.0+4 more2020-03-24
CVE-2019-20624 [MEDIUM] CWE-306 CVE-2019-20624: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks key
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Samsung ID is SVE-2018-12981 (February 2019).
nvd
CVE-2015-6611P4MEDIUMCVSS 5.0≥ 5.0, < 5.1.1v6.02015-11-03
CVE-2015-6611 [MEDIUM] CWE-200 CVE-2015-6611: mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obta
mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23905951, 23912202, 23953967, 23696300, 23600291, 23756261, 23541506, 23284974, 23542351, and 23542352, a different vulnerabili
nvd
CVE-2021-25347P4MEDIUMCVSS 5.3v9.0v10.0+1 more2021-03-04
CVE-2021-25347 [MEDIUM] CWE-287 CVE-2021-25347: Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows
Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.
nvd
CVE-2015-3861P4MEDIUMCVSS 5.0≤ 5.12015-10-01
CVE-2015-3861 [MEDIUM] CWE-189 CVE-2015-3861: Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in l
Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denial of service (device inoperability) via crafted Matroska data, aka internal bug 21296336.
nvd
CVE-2024-27223P4MEDIUMCVSS 5.1v13.0v132024-03-11
CVE-2024-27223 [MEDIUM] CWE-125 CVE-2024-27223: In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bo
In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure after authenticating the cell connection with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-56193P4MEDIUMCVSS 5.1vAndroid kernel2025-05-27
CVE-2024-56193 [MEDIUM] CWE-200 CVE-2024-56193: There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47030P4MEDIUMCVSS 5.1vAndroid kernel2024-10-25
CVE-2024-47030 [MEDIUM] CVE-2024-47030: Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM componen
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.
nvd
CVE-2024-56184P4MEDIUMCVSS 5.1vAndroid kernel2025-03-10
CVE-2024-56184 [MEDIUM] CWE-125 CVE-2024-56184: In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect b
In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-56186P4MEDIUMCVSS 5.1vAndroid kernel2025-03-10
CVE-2024-56186 [MEDIUM] CWE-125 CVE-2024-56186: In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect
In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27230P4MEDIUMCVSS 5.1v13.0v132024-03-11
CVE-2024-27230 [MEDIUM] CWE-125 CVE-2024-27230: In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of
In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2020-0093P4MEDIUMCVSS 5.0v8.0v8.1+2 more2020-05-14
CVE-2020-0093 [MEDIUM] CWE-125 CVE-2020-0093: In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
nvd