Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 298 of 339
CVE-2022-42755P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42755 [MEDIUM] CWE-787 CVE-2022-42755: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2022-47323P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47323 [MEDIUM] CWE-125 CVE-2022-47323: In wlan driver, there is a possible missing params check. This could lead to local denial of service
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
nvd
CVE-2022-42765P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42765 [MEDIUM] CWE-190 CVE-2022-42765: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2022-42772P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42772 [MEDIUM] CWE-787 CVE-2022-42772: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2019-20575P4MEDIUMCVSS 5.4v9.02020-03-24
CVE-2019-20575 [MEDIUM] CWE-916 CVE-2019-20575: An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature a
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).
nvd
CVE-2015-6629P4MEDIUMCVSS 5.0≤ 5.12015-12-08
CVE-2015-6629 [MEDIUM] CWE-200 CVE-2015-6629: Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspec
Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22667667.
nvd
CVE-2018-9438P4MEDIUMCVSS 5.0v8.12018-11-06
CVE-2018-9438 [MEDIUM] CVE-2018-9438: When a device connects only over WiFi VPN, the device may not receive security updates due to some i
When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.1 Android ID: A-78644887.
nvd
CVE-2022-20195P4MEDIUMCVSS 5.0v12.1vAndroid-12L2022-06-15
CVE-2022-20195 [MEDIUM] CWE-502 CVE-2022-20195: In the keystore library, there is a possible prevention of access to system Settings due to unsafe d
In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-213172664
nvd
CVE-2020-0031P4MEDIUMCVSS 5.0v10.0vAndroid-102020-03-10
CVE-2020-0031 [MEDIUM] CWE-200 CVE-2020-0031: In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmente
In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to display sensitive information to the user inappropriately. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Andr
nvd
CVE-2021-0687P4MEDIUMCVSS 5.0v8.1v9.0+3 more2021-10-06
CVE-2021-0687 [MEDIUM] CWE-834 CVE-2021-0687: In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could le
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-188913943
nvd
CVE-2021-1023P4MEDIUMCVSS 5.0v12.0vAndroid-122021-12-15
CVE-2021-1023 [MEDIUM] CWE-200 CVE-2021-1023: In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether
In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersio
nvd
CVE-2021-0919P4MEDIUMCVSS 5.0v9.0v10.0+2 more2021-12-15
CVE-2021-0919 [MEDIUM] CWE-190 CVE-2021-0919: In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer over
In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-197336441
nvd
CVE-2023-21090P4MEDIUMCVSS 5.0v13.0vAndroid-132023-04-19
CVE-2023-21090 [MEDIUM] CWE-400 CVE-2023-21090: In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource ex
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259942609
nvd
CVE-2016-8414P4MEDIUMCVSS 4.7≤ 7.1.12017-02-08
CVE-2016-8414 [MEDIUM] CWE-200 CVE-2016-8414: An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator co
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31
nvd
CVE-2017-0451P4MEDIUMCVSS 4.7≤ 7.1.12017-02-08
CVE-2017-0451 [MEDIUM] CWE-200 CVE-2017-0451: An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious
An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31796345. References: QC-CR#1073
nvd
CVE-2017-8281P4MEDIUMCVSS 4.7≤ 8.02017-09-21
CVE-2017-8281 [MEDIUM] CWE-200 CVE-2017-8281: In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
nvd
CVE-2022-33691P4MEDIUMCVSS 4.7v10.0v11.0+1 more2022-07-12
CVE-2022-33691 [MEDIUM] CWE-367 CVE-2022-33691: A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow lo
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.
nvd
CVE-2016-11041P4MEDIUMCVSS 4.6v4.42020-04-07
CVE-2016-11041 [MEDIUM] CWE-287 CVE-2016-11041: An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lo
An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).
nvd
CVE-2022-25816P4MEDIUMCVSS 4.6v10.0v11.0+1 more2022-03-10
CVE-2022-25816 [MEDIUM] CWE-287 CVE-2022-25816: Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
nvd
CVE-2025-48614P4MEDIUMCVSS 4.6v13.0v14.0+6 more2025-12-08
CVE-2025-48614 [MEDIUM] CWE-862 CVE-2025-48614: In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device wh
In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check. This could lead to physical denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd