Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 279 of 339
CVE-2016-3834P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-08-05
CVE-2016-3834 [MEDIUM] CWE-200 CVE-2016-3834: The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.
nvd
CVE-2017-11040P4MEDIUMCVSS 5.5≤ 8.02017-09-21
CVE-2017-11040 [MEDIUM] CWE-200 CVE-2017-11040: In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sy
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
nvd
CVE-2017-0492P4MEDIUMCVSS 5.5v7.0v7.1.0+1 more2017-03-08
CVE-2017-0492 [MEDIUM] CWE-1021 CVE-2017-0492: An elevation of privilege vulnerability in the System UI could enable a local malicious application
An elevation of privilege vulnerability in the System UI could enable a local malicious application to create a UI overlay covering the entire screen. This issue is rated as Moderate because it is a local bypass of user interaction requirements that would normally require either user initiation or user permission. Product: Android. Versions: 7.1.1. An
nvd
CVE-2016-2499P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-06-13
CVE-2016-2499 [MEDIUM] CWE-200 CVE-2016-2499: AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.
AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not initialize certain data, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 27855172.
nvd
CVE-2016-6715P4MEDIUMCVSS 5.5≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-11-25
CVE-2016-6715 [MEDIUM] CWE-275 CVE-2016-6715: An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x bef
An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the user's permission. This issue is rated as Moderate because it is a local bypass of user interaction req
nvd
CVE-2017-0625P4MEDIUMCVSS 5.5≤ 7.1.22017-05-12
CVE-2017-0625 [MEDIUM] CWE-200 CVE-2017-0625: An information disclosure vulnerability in the MediaTek command queue driver could enable a local ma
An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-35142799. References: M-A
nvd
CVE-2016-6910P4MEDIUMCVSS 5.5v5.0.2v5.1.1+1 more2016-12-23
CVE-2016-6910 [MEDIUM] CWE-200 CVE-2016-6910: The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 bui
The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung Galaxy S6 Edge devices, but the vulnerability can persist on the device even after the device has been upgraded to an Android 5.1.1 or 6.0.1 build. The vulnerable system app gives a non-existent app the ability to read the notificati
nvd
CVE-2016-6719P4MEDIUMCVSS 5.5≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-11-25
CVE-2016-6719 [MEDIUM] CWE-275 CVE-2016-6719: An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.
An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair with any Bluetooth device without user consent. This issue is rated as Moderate because it is a local bypass of user
nvd
CVE-2016-6716P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6716 [MEDIUM] CWE-284 CVE-2016-6716: An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could
An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally r
nvd
CVE-2017-0395P4MEDIUMCVSS 5.5v4.0v4.0.1+25 more2017-01-12
CVE-2017-0395 [MEDIUM] CVE-2017-0395: An elevation of privilege vulnerability in Contacts could enable a local malicious application to si
An elevation of privilege vulnerability in Contacts could enable a local malicious application to silently create contact information. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Product: Android. Versions: 4.4.4,
nvd
CVE-2019-14783P4MEDIUMCVSS 5.5v7.0v7.1.0+5 more2019-08-08
CVE-2019-14783 [MEDIUM] CVE-2019-14783: On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious app
On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files. The Samsung ID is SVE-2019-14764.
nvd
CVE-2019-9373P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9373 [MEDIUM] CWE-502 CVE-2019-9373: In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attri
In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-130173029
nvd
CVE-2021-25454P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-09-09
CVE-2021-25454 [MEDIUM] CWE-125 CVE-2021-25454: OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attacke
OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
nvd
CVE-2017-13275P4MEDIUMCVSS 5.5v8.0v8.12018-04-04
CVE-2017-13275 [MEDIUM] CWE-125 CVE-2017-13275: In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bou
In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-70808908.
nvd
CVE-2019-2137P4MEDIUMCVSS 5.5v9.0vAndroid-92019-08-20
CVE-2019-2137 [MEDIUM] CWE-862 CVE-2019-2137: In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a mis
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-132438333.
nvd
CVE-2020-25046P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-08-31
CVE-2020-25046 [MEDIUM] CWE-532 CVE-2020-25046: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).
nvd
CVE-2020-11601P4MEDIUMCVSS 5.5v9.0v10.02020-04-08
CVE-2020-11601 [MEDIUM] CVE-2020-11601: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is unautho
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is unauthorized access to applications in the Secure Folder via floating icons. The Samsung ID is SVE-2019-16195 (April 2020).
nvd
CVE-2020-0004P4MEDIUMCVSS 5.5v8.0v8.1+6 more2020-01-08
CVE-2020-0004 [MEDIUM] CWE-755 CVE-2020-0004: In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceed
In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-1208
nvd
CVE-2022-39116P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-39116 [MEDIUM] CWE-121 CVE-2022-39116: In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This
In sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
nvd
CVE-2022-38687P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38687 [MEDIUM] CWE-400 CVE-2022-38687: In messaging service, there is a missing permission check. This could lead to local denial of servic
In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed.
nvd