Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 287 of 339
CVE-2024-32904P4MEDIUMCVSS 4.7vAndroid kernel2024-06-13
CVE-2024-32904 [MEDIUM] CWE-125 CVE-2024-32904: In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read
In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
nvd
CVE-2024-32898P4MEDIUMCVSS 4.7vAndroid kernel2024-06-13
CVE-2024-32898 [MEDIUM] CWE-125 CVE-2024-32898: In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bound
In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
nvd
CVE-2024-29778P4MEDIUMCVSS 4.7vAndroid kernel2024-06-13
CVE-2024-29778 [MEDIUM] CWE-125 CVE-2024-29778: In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possib
In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2009-1754P4MEDIUMCVSS 4.3v1.52009-05-26
CVE-2009-1754 [MEDIUM] CWE-287 CVE-2009-1754: The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in An
The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package tha
nvd
CVE-2021-25482P4MEDIUMCVSS 4.4v11.02021-10-06
CVE-2021-25482 [MEDIUM] CWE-264 CVE-2021-25482: SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted appl
SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.
nvd
CVE-2024-44096P4MEDIUMCVSS 4.4vAndroid kernel2024-09-13
CVE-2024-44096 [MEDIUM] CWE-1188 CVE-2024-44096: there is a possible arbitrary read due to an insecure default value. This could lead to local inform
there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-39855P4MEDIUMCVSS 4.3v10.0v11.0+1 more2022-10-07
CVE-2022-39855 [MEDIUM] CWE-284 CVE-2022-39855: Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a l
Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.
nvd
CVE-2016-0808P4MEDIUMCVSS 6.2v5.0v5.0.1+6 more2016-02-07
CVE-2016-0808 [MEDIUM] CWE-19 CVE-2016-0808: Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in A
Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.
nvd
CVE-2017-0393P4MEDIUMCVSS 5.5v4.0v4.0.1+25 more2017-01-12
CVE-2017-0393 [MEDIUM] CVE-2017-0393: A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a s
A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.
nvd
CVE-2016-3881P4MEDIUMCVSS 5.5v4.0v4.0.1+21 more2016-09-11
CVE-2016-3881 [MEDIUM] CWE-119 CVE-2016-3881: The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x
The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of service (buffer over-read, and device hang or reboot) via a crafted media file, aka internal bug 30013856.
nvd
CVE-2016-6711P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-12-13
CVE-2016-6711 [MEDIUM] CWE-20 CVE-2016-6711: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765
nvd
CVE-2017-0548P4MEDIUMCVSS 5.5v7.0v7.1.0+1 more2017-04-07
CVE-2017-0548 [MEDIUM] CWE-119 CVE-2017-0548: A remote denial of service vulnerability in libskia could enable an attacker to use a specially craf
A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33251605.
nvd
CVE-2016-6712P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-12-13
CVE-2016-6712 [MEDIUM] CWE-20 CVE-2016-6712: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593752
nvd
CVE-2016-3920P4MEDIUMCVSS 5.5v5.0v5.0.1+5 more2016-10-10
CVE-2016-3920 [MEDIUM] CWE-20 CVE-2016-3920: id3/ID3.cpp in libstagefright in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x
id3/ID3.cpp in libstagefright in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 30744884.
nvd
CVE-2017-0642P4MEDIUMCVSS 5.5v5.0.2v5.1.1+5 more2017-06-14
CVE-2017-0642 [MEDIUM] CVE-2017-0642: A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34819017.
nvd
CVE-2017-0549P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0549 [MEDIUM] CVE-2017-0549: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818508.
nvd
CVE-2017-0552P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0552 [MEDIUM] CVE-2017-0552: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097915.
nvd
CVE-2017-0550P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-04-07
CVE-2017-0550 [MEDIUM] CVE-2017-0550: A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33933140.
nvd
CVE-2017-0599P4MEDIUMCVSS 5.5v6.0v6.0.1+4 more2017-05-12
CVE-2017-0599 [MEDIUM] CWE-252 CVE-2017-0599: A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34672748.
nvd
CVE-2017-0391P4MEDIUMCVSS 5.5v6.0v6.0.1+2 more2017-01-12
CVE-2017-0391 [MEDIUM] CVE-2017-0391: A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable
A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32322258.
nvd