Google Android vulnerabilities

7,234 known vulnerabilities affecting google/android.

Total CVEs
7,234
CISA KEV
18
actively exploited
Public exploits
52
Exploited in wild
18
Severity breakdown
CRITICAL544HIGH2984MEDIUM3458LOW248

Vulnerabilities

Page 28 of 362
CVE-2018-9434HIGHCVSS 7.8v6.0v6.0.1+6 more2025-01-17
CVE-2018-9434 [HIGH] CWE-276 CVE-2018-9434: In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomiz In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9383MEDIUMCVSS 4.4vAndroid kernel2025-01-17
CVE-2018-9383 [MEDIUM] CWE-125 CVE-2018-9383: In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bound In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9447MEDIUMCVSS 5.5v6.0v6.0.1+3 more2025-01-17
CVE-2018-9447 [MEDIUM] CWE-400 CVE-2018-9447: In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9379MEDIUMCVSS 5.5v6.0v6.0.1+6 more2025-01-17
CVE-2018-9379 [MEDIUM] CWE-200 CVE-2018-9379: In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of delet In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9384MEDIUMCVSS 4.4vAndroid Kernel2025-01-17
CVE-2018-9384 [MEDIUM] CWE-200 CVE-2018-9384: In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This co In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2023-35685HIGHCVSS 7.8vAndroid SoC2025-01-08
CVE-2023-35685 [HIGH] CWE-416 CVE-2023-35685: In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic err In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-20148CRITICALCVSS 9.8v13.0v14.0+1 more2025-01-06
CVE-2024-20148 [CRITICAL] CWE-787 CVE-2024-20148: In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.
nvd
CVE-2024-20146HIGHCVSS 8.1v13.0v14.0+1 more2025-01-06
CVE-2024-20146 [HIGH] CWE-787 CVE-2024-20146: In wlan STA driver, there is a possible out of bounds write due to improper input validation. This c In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.
nvd
CVE-2024-20153HIGHCVSS 7.5v14.0v15.02025-01-06
CVE-2024-20153 [HIGH] CWE-304 CVE-2024-20153: In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This c In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
nvd
CVE-2024-20144MEDIUMCVSS 6.6v13.0v14.0+1 more2025-01-06
CVE-2024-20144 [MEDIUM] CWE-787 CVE-2024-20144: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041.
nvd
CVE-2024-20145MEDIUMCVSS 6.6v14.0v15.02025-01-06
CVE-2024-20145 [MEDIUM] CWE-787 CVE-2024-20145: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.
nvd
CVE-2024-20105MEDIUMCVSS 6.7v12.0v13.0+2 more2025-01-06
CVE-2024-20105 [MEDIUM] CWE-787 CVE-2024-20105: In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09062027; Issue ID: MSV-1743.
nvd
CVE-2024-20143MEDIUMCVSS 6.6v12.0v13.0+2 more2025-01-06
CVE-2024-20143 [MEDIUM] CWE-787 CVE-2024-20143: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069.
nvd
CVE-2024-20152MEDIUMCVSS 4.4v13.0v14.0+1 more2025-01-06
CVE-2024-20152 [MEDIUM] CWE-617 CVE-2024-20152: In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
nvd
CVE-2024-20140MEDIUMCVSS 6.7v12.0v13.0+2 more2025-01-06
CVE-2024-20140 [MEDIUM] CWE-787 CVE-2024-20140: In power, there is a possible out of bounds write due to a missing bounds check. This could lead to In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020.
nvd
CVE-2024-53842CRITICALCVSS 9.8vAndroid kernel2025-01-03
CVE-2024-53842 [CRITICAL] CWE-787 CVE-2024-53842: In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-43762HIGHCVSS 7.8v12.0v12.1+8 more2025-01-03
CVE-2024-43762 [HIGH] CVE-2024-43762: In multiple locations, there is a possible way to avoid unbinding of a service from the system due t In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-47032HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-47032 [HIGH] CWE-120 CVE-2024-47032: In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-53834HIGHCVSS 7.5vAndroid kernel2025-01-03
CVE-2024-53834 [HIGH] CWE-125 CVE-2024-53834: In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-53840HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-53840 [HIGH] CWE-276 CVE-2024-53840: there is a possible biometric bypass due to an unusual root cause. This could lead to local escalati there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd