Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 295 of 339
CVE-2017-0669P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-07-06
CVE-2017-0669 [MEDIUM] CWE-200 CVE-2017-0669: A information disclosure vulnerability in the Android framework. Product: Android. Versions: 6.0, 6.
A information disclosure vulnerability in the Android framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34114752.
nvd
CVE-2017-0668P4MEDIUMCVSS 5.5v4.4.4v5.0.2+6 more2017-07-06
CVE-2017-0668 [MEDIUM] CWE-200 CVE-2017-0668: A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4,
A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-22011579.
nvd
CVE-2017-0779P4MEDIUMCVSS 5.5v4.0v4.0.1+27 more2017-09-08
CVE-2017-0779 [MEDIUM] CWE-200 CVE-2017-0779: A information disclosure vulnerability in the Android media framework (audioflinger). Product: Andro
A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117.
nvd
CVE-2017-0698P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-07-06
CVE-2017-0698 [MEDIUM] CWE-200 CVE-2017-0698: A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6
A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35467458.
nvd
CVE-2017-0699P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-07-06
CVE-2017-0699 [MEDIUM] CWE-200 CVE-2017-0699: A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6
A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36490809.
nvd
CVE-2014-9798P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2014-9798 [MEDIUM] CWE-284 CVE-2014-9798: platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 de
platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS outage) via a crafted application, aka Android internal bug 28821448 and Qualcomm internal bug CR681965.
nvd
CVE-2021-22494P4MEDIUMCVSS 5.5v10.02021-01-05
CVE-2021-22494 [MEDIUM] CVE-2021-22494: An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) sof
An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) software. When a screen protector is used, the required image compensation is not present. Consequently, inversion can occur during fingerprint enrollment, and a high False Recognition Rate (FRR) can occur. The Samsung ID is SVE-2020-19216 (January 2021).
nvd
CVE-2021-22495P4MEDIUMCVSS 5.5v8.0v8.1+3 more2021-01-05
CVE-2021-22495 [MEDIUM] CWE-787 CVE-2021-22495: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung ID is SVE-2020-19174 (January 2021).
nvd
CVE-2017-0498P4MEDIUMCVSS 5.5v5.0v5.0.1+9 more2017-03-08
CVE-2017-0498 [MEDIUM] CVE-2017-0498: A denial of service vulnerability in Setup Wizard could allow a local attacker to require Google acc
A denial of service vulnerability in Setup Wizard could allow a local attacker to require Google account sign-in after a factory reset. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-30352311.
nvd
CVE-2022-47451P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47451 [MEDIUM] CWE-190 CVE-2022-47451: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd
CVE-2016-3853P4MEDIUMCVSS 5.5≤ 6.0.12016-08-05
CVE-2016-3853 [MEDIUM] CWE-264 CVE-2016-3853: Google Play services in Android before 2016-08-05 on Nexus devices allow local users to bypass the F
Google Play services in Android before 2016-08-05 on Nexus devices allow local users to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26803208.
nvd
CVE-2020-13843P4MEDIUMCVSS 5.5fixed in 2020-06-012020-06-05
CVE-2020-13843 [MEDIUM] CVE-2020-13843: An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).
nvd
CVE-2021-25345P4MEDIUMCVSS 5.5v10.0v11.02021-03-04
CVE-2021-25345 [MEDIUM] CVE-2021-25345: Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1
Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.
nvd
CVE-2022-39133P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-39133 [MEDIUM] CWE-787 CVE-2022-39133: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2021-25452P4MEDIUMCVSS 5.5v10.0v11.02021-09-09
CVE-2021-25452 [MEDIUM] CWE-22 CVE-2021-25452: An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.
nvd
CVE-2022-38681P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-38681 [MEDIUM] CWE-191 CVE-2022-38681: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd
CVE-2022-38674P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-38674 [MEDIUM] CWE-190 CVE-2022-38674: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd
CVE-2022-38680P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-38680 [MEDIUM] CWE-190 CVE-2022-38680: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd
CVE-2022-47368P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47368 [MEDIUM] CWE-787 CVE-2022-47368: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd
CVE-2022-47369P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47369 [MEDIUM] CWE-787 CVE-2022-47369: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd