cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 277 of 339
CVE-2021-0660P4MEDIUMCVSS 4.9v10.0v11.02021-09-27
CVE-2021-0660 [MEDIUM] CWE-125 CVE-2021-0660: In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to i In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827145; Issue ID: ALPS05827145.
nvd
CVE-2021-0322P4MEDIUMCVSS 5.0v9.0v10.0+4 more2021-01-11
CVE-2021-0322 [MEDIUM] CWE-20 CVE-2021-0322: In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android; Versions: Android-10, Android-11, Android-9; Android ID: A-159145361.
nvd
CVE-2021-0973P4MEDIUMCVSS 5.0v12.0vAndroid-122021-12-15
CVE-2021-0973 [MEDIUM] CWE-178 CVE-2021-0973: In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due t In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178
nvd
CVE-2023-21307P4MEDIUMCVSS 5.0fixed in 14.0v142023-10-30
CVE-2023-21307 [MEDIUM] CWE-287 CVE-2023-21307: In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-21190P4MEDIUMCVSS 5.0v13.0vAndroid-132023-06-28
CVE-2023-21190 [MEDIUM] CVE-2023-21190: In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off enc In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13
nvd
CVE-2026-0142P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0142 CVE-2026-0142: In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input va In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21095P4MEDIUMCVSS 4.7v12.1v13.0+1 more2023-06-15
CVE-2023-21095 [MEDIUM] CWE-362 CVE-2023-21095: In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-242704576
nvd
CVE-2020-10847P4MEDIUMCVSS 6.8v9.02020-03-24
CVE-2020-10847 [MEDIUM] CWE-287 CVE-2020-10847: An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).
nvd
CVE-2014-9908P4MEDIUMCVSS 6.5v4.4v5.0.2+3 more2020-01-08
CVE-2014-9908 [MEDIUM] CVE-2014-9908: A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows mal A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).
nvd
CVE-2019-20546P4MEDIUMCVSS 6.5v7.0v7.1.0+5 more2020-03-24
CVE-2019-20546 [MEDIUM] CVE-2019-20546: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom Wi-Fi ch An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom Wi-Fi chipsets) software. A denial-of-service attack can leverage a shared interface between Broadcom Bluetooth and Broadcom Wi-Fi. The Samsung ID is SVE-2019-15350 (November 2019).
nvd
CVE-2019-20535P4MEDIUMCVSS 6.2v8.0v8.1+1 more2020-03-24
CVE-2019-20535 [MEDIUM] CVE-2019-20535: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devices can be established from the lock screen. The Samsung ID is SVE-2019-15533 (December 2019).
nvd
CVE-2025-31711P4MEDIUMCVSS 6.2v13.0v14.0+1 more2025-06-03
CVE-2025-31711 [MEDIUM] CWE-476 CVE-2025-31711: In cplog service, there is a possible system crash due to null pointer dereference. This could lead In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional execution privileges needed.
nvd
CVE-2017-0551P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0551 [MEDIUM] CVE-2017-0551: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097231.
nvd
CVE-2018-9452P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9452 [MEDIUM] CWE-20 CVE-2018-9452: In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width c In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width calculation. This could lead to remote denial of service if a contact with many hidden unicode characters were sent to the device and used by a local app, with no additional execution privileges needed. User interaction is needed for exploitation. Product
nvd
CVE-2016-3899P4MEDIUMCVSS 5.5v4.0v4.0.1+21 more2016-09-11
CVE-2016-3899 [MEDIUM] CWE-284 CVE-2016-3899: OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not validate a certain pointer, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29421811.
nvd
CVE-2016-3829P4MEDIUMCVSS 5.5v6.0v6.0.12016-08-05
CVE-2016-3829 [MEDIUM] CWE-172 CVE-2016-3829: The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain struc The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29023649.
nvd
CVE-2017-0426P4MEDIUMCVSS 5.5v7.0v7.1.0+1 more2017-02-08
CVE-2017-0426 [MEDIUM] CWE-200 CVE-2017-0426: An information disclosure vulnerability in the Filesystem could enable a local malicious application An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32799236.
nvd
CVE-2017-0557P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0557 [MEDIUM] CWE-200 CVE-2017-0557: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious ap An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093073.
nvd
CVE-2017-0558P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-04-07
CVE-2017-0558 [MEDIUM] CWE-200 CVE-2017-0558: An information disclosure vulnerability in Mediaserver could enable a local malicious application to An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34056274.
nvd
CVE-2015-8944P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2015-8944 [MEDIUM] CWE-200 CVE-2015-8944: The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Andro The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information by reading this file, aka Android internal bug 28814213 and Qualcomm internal bug CR786116. NOTE: the p
nvd
Google Android vulnerabilities | cvebase