Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 288 of 339
CVE-2017-0390P4MEDIUMCVSS 5.5v4.0v4.0.1+25 more2017-01-12
CVE-2017-0390 [MEDIUM] CVE-2017-0390: A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to
A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31647370.
nvd
CVE-2017-0392P4MEDIUMCVSS 5.5v4.0v4.0.1+25 more2017-01-12
CVE-2017-0392 [MEDIUM] CVE-2017-0392: A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a
A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.
nvd
CVE-2017-0643P4MEDIUMCVSS 5.5v5.0.2v5.1.1+4 more2017-06-14
CVE-2017-0643 [MEDIUM] CVE-2017-0643: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-35645051.
nvd
CVE-2017-0425P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-02-08
CVE-2017-0425 [MEDIUM] CWE-200 CVE-2017-0425: An information disclosure vulnerability in Audioserver could enable a local malicious application to
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32720785.
nvd
CVE-2016-3892P4MEDIUMCVSS 5.5≤ 7.02016-09-11
CVE-2016-3892 [MEDIUM] CWE-200 CVE-2016-3892: The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attac
The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28760543 and Qualcomm internal bug CR1024197.
nvd
CVE-2017-0738P4MEDIUMCVSS 5.5v4.0v4.0.1+27 more2017-08-09
CVE-2017-0738 [MEDIUM] CWE-200 CVE-2017-0738: A information disclosure vulnerability in the Android media framework (audioserver). Product: Androi
A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.
nvd
CVE-2016-3896P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-09-11
CVE-2016-3896 [MEDIUM] CWE-200 CVE-2016-3896: AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-0
AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attackers to obtain sensitive EmailAccountCacheProvider information via a crafted application, aka internal bug 29767043.
nvd
CVE-2017-0815P4MEDIUMCVSS 5.5v4.0v4.0.1+28 more2017-10-04
CVE-2017-0815 [MEDIUM] CWE-200 CVE-2017-0815: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.
nvd
CVE-2017-0816P4MEDIUMCVSS 5.5v4.0v4.0.1+28 more2017-10-04
CVE-2017-0816 [MEDIUM] CWE-200 CVE-2017-0816: An information disclosure vulnerability in the Android media framework (libeffects). Product: Androi
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63662938.
nvd
CVE-2017-0397P4MEDIUMCVSS 5.5v4.0v4.0.1+25 more2017-01-12
CVE-2017-0397 [MEDIUM] CWE-200 CVE-2017-0397: An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.
nvd
CVE-2017-0647P4MEDIUMCVSS 5.5v5.0.2v5.1.1+5 more2017-06-14
CVE-2017-0647 [MEDIUM] CWE-200 CVE-2017-0647: An information disclosure vulnerability in libziparchive could enable a local malicious application
An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36392138.
nvd
CVE-2017-0635P4MEDIUMCVSS 5.5v7.0v7.1.0+2 more2017-05-12
CVE-2017-0635 [MEDIUM] CWE-476 CVE-2017-0635: A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could ena
A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerability. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35467107.
nvd
CVE-2016-6773P4MEDIUMCVSS 5.5v6.0v6.0.1+1 more2017-01-12
CVE-2016-6773 [MEDIUM] CWE-200 CVE-2016-6773: An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local ma
An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-30481714.
nvd
CVE-2016-2454P4MEDIUMCVSS 5.5≤ 6.0.12016-05-09
CVE-2016-2454 [MEDIUM] CWE-20 CVE-2016-2454: The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote atta
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
nvd
CVE-2016-3895P4MEDIUMCVSS 5.5v6.0v6.0.1+1 more2016-09-11
CVE-2016-3895 [MEDIUM] CWE-190 CVE-2016-3895: Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6
Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 29983260.
nvd
CVE-2016-3837P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-08-05
CVE-2016-3837 [MEDIUM] CWE-200 CVE-2016-3837: service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x bef
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few characters, aka internal bug 28164077.
nvd
CVE-2017-0600P4MEDIUMCVSS 5.5v4.0v4.0.1+27 more2017-05-12
CVE-2017-0600 [MEDIUM] CVE-2017-0600: A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker t
A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35269635.
nvd
CVE-2016-3815P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3815 [MEDIUM] CWE-200 CVE-2016-3815: The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28522274.
nvd
CVE-2016-3813P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3813 [MEDIUM] CWE-200 CVE-2016-3813: The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attack
The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28172322 and Qualcomm internal bug CR1010222.
nvd
CVE-2017-0495P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0495 [MEDIUM] CWE-200 CVE-2017-0495: An information disclosure vulnerability in Mediaserver could enable a local malicious application to
An information disclosure vulnerability in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33552073.
nvd