Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 289 of 339
CVE-2016-6683P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6683 [MEDIUM] CWE-200 CVE-2016-6683: The kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive inform
The kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30143283.
nvd
CVE-2017-0529P4MEDIUMCVSS 5.5≤ 7.1.12017-03-08
CVE-2017-0529 [MEDIUM] CWE-200 CVE-2017-0529: An information disclosure vulnerability in the MediaTek driver could enable a local malicious applic
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-28449427. References: M-ALPS02710042.
nvd
CVE-2016-3894P4MEDIUMCVSS 5.5≤ 7.02016-09-11
CVE-2016-3894 [MEDIUM] CWE-200 CVE-2016-3894: The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtai
The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29618014 and Qualcomm internal bug CR1042033.
nvd
CVE-2017-0602P4MEDIUMCVSS 5.5v4.0v4.0.1+27 more2017-05-12
CVE-2017-0602 [MEDIUM] CWE-200 CVE-2017-0602: An information disclosure vulnerability in Bluetooth could allow a local malicious application to by
An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Androi
nvd
CVE-2016-6684P4MEDIUMCVSS 5.5v7.02016-10-10
CVE-2016-6684 [MEDIUM] CWE-200 CVE-2016-6684: The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus Play
The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Android One devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30148243.
nvd
CVE-2016-6685P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6685 [MEDIUM] CWE-200 CVE-2016-6685: The kernel in Android before 2016-10-05 on Nexus 6P devices allows attackers to obtain sensitive inf
The kernel in Android before 2016-10-05 on Nexus 6P devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30402628.
nvd
CVE-2017-0601P4MEDIUMCVSS 5.5v7.0v7.1.0+2 more2017-05-12
CVE-2017-0601 [MEDIUM] CWE-732 CVE-2017-0601: An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious appl
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.
nvd
CVE-2017-0491P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-03-08
CVE-2017-0491 [MEDIUM] CVE-2017-0491: An elevation of privilege vulnerability in Package Manager could enable a local malicious applicatio
An elevation of privilege vulnerability in Package Manager could enable a local malicious application to prevent users from uninstalling applications or removing permissions from applications. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1.
nvd
CVE-2016-3814P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3814 [MEDIUM] CWE-200 CVE-2016-3814: The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28193342.
nvd
CVE-2016-3810P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3810 [MEDIUM] CWE-200 CVE-2016-3810: The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to ob
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28175522 and MediaTek internal bug ALPS02694389.
nvd
CVE-2016-3816P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3816 [MEDIUM] CWE-200 CVE-2016-3816: The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to
The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28402240.
nvd
CVE-2016-3812P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3812 [MEDIUM] CWE-200 CVE-2016-3812: The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers
The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28174833 and MediaTek internal bug ALPS02688832.
nvd
CVE-2016-3809P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2016-3809 [MEDIUM] CWE-200 CVE-2016-3809: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Ne
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.
nvd
CVE-2016-8396P4MEDIUMCVSS 5.5≤ 7.1.02017-01-12
CVE-2016-8396 [MEDIUM] CWE-200 CVE-2016-8396: An information disclosure vulnerability in the MediaTek video driver could enable a local malicious
An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-31249105.
nvd
CVE-2016-3852P4MEDIUMCVSS 5.5≤ 6.0.12016-08-05
CVE-2016-3852 [MEDIUM] CWE-200 CVE-2016-3852: The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to ob
The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29141147 and MediaTek internal bug ALPS02751738.
nvd
CVE-2015-3840P4MEDIUMCVSS 5.5≤ 5.1.12017-06-27
CVE-2015-3840 [MEDIUM] CWE-284 CVE-2015-3840: The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows loc
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
nvd
CVE-2022-20453P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-11-08
CVE-2022-20453 [MEDIUM] CWE-22 CVE-2022-20453: In update of MmsProvider.java, there is a possible constriction of directory permissions due to a pa
In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android
nvd
CVE-2020-0087P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0087 [MEDIUM] CWE-863 CVE-2020-0087: In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclo
In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127989044
nvd
CVE-2020-35549P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-12-18
CVE-2020-35549 [MEDIUM] CVE-2020-35549: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any app
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establish itself as the default dialer, without user interaction. The Samsung ID is SVE-2020-19172 (December 2020).
nvd
CVE-2020-0263P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0263 [MEDIUM] CVE-2020-0263: In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent.
In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154913130
nvd