Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 3 of 339
CVE-2015-3829P2CRITICALCVSS 10.0≤ 5.12015-10-01
CVE-2015-3829 [CRITICAL] CWE-189 CVE-2015-3829: Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright
Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted MPEG-4 covr atoms with a size equal to SIZE_MAX, aka internal bug 20923261.
nvd
CVE-2015-1539P2CRITICALCVSS 10.0≤ 5.12015-10-01
CVE-2015-1539 [CRITICAL] CWE-189 CVE-2015-1539: Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.
nvd
CVE-2013-6792P3CRITICALCVSS 9.8PoCfixed in 4.42020-01-23
CVE-2013-6792 [CRITICAL] CVE-2013-6792: Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
nvd
CVE-2015-3827P2CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3827 [CRITICAL] CWE-119 CVE-2015-3827: The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship between chunk sizes and skip sizes, which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted MPEG-4 covr atoms, aka interna
nvd
CVE-2015-3828P2CRITICALCVSS 10.0≤ 5.12015-10-01
CVE-2015-3828 [CRITICAL] CVE-2015-3828: The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android be
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted 3GPP metadata,
nvd
CVE-2013-6271P3HIGHCVSS 8.8PoCv4.0v4.0.1+9 more2013-12-14
CVE-2013-6271 [HIGH] CWE-264 CVE-2013-6271: Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device lo
Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the updateUnlockMethodAndFinish method in the com.android.settings.ChooseLockGeneric class with the PASSWORD_QUALITY_UNSPECIFIED option.
nvd
CVE-2016-3861P3HIGHCVSS 7.8PoCv4.0v4.0.1+21 more2016-09-11
CVE-2016-3861 [HIGH] CWE-119 CVE-2016-3861: LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01,
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted file, aka
nvd
CVE-2017-7376P2CRITICALCVSS 9.8v4.4.4v5.0.2+6 more2018-02-19
CVE-2017-7376 [CRITICAL] CWE-119 CVE-2017-7376: Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorr
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
nvd
CVE-2014-8507P3HIGHCVSS 7.5PoC≤ 4.4.4v1.0+41 more2014-12-15
CVE-2014-8507 [HIGH] CWE-89 CVE-2014-8507: Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a
nvd
CVE-2014-0997P3HIGHCVSS 7.5PoCv4.4.4v4.2.2+1 more2017-09-26
CVE-2014-0997 [HIGH] CWE-19 CVE-2014-0997: WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, And
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1 and 5.0.2 does not properly handle exceptions, which allows remote attackers to cause a denial of serv
nvd
CVE-2014-9322P3HIGHCVSS 7.8PoCv6.0v6.0.12014-12-17
CVE-2014-9322 [HIGH] CWE-269 CVE-2014-9322: arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associa
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
nvd
CVE-2016-6707P3HIGHCVSS 7.8PoC≥ 6.0, ≤ 6.0.1v7.02016-11-25
CVE-2016-6707 [HIGH] CWE-264 CVE-2016-6707: An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 be
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally acc
nvd
CVE-2015-6639P3HIGHCVSS 7.8PoCv5.0v5.1.1+2 more2016-01-06
CVE-2015-6639 [HIGH] CWE-264 CVE-2015-6639: The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.
nvd
CVE-2017-13253P3HIGHCVSS 7.8PoCv8.0v8.12018-04-04
CVE-2017-13253 [HIGH] CWE-787 CVE-2017-13253: In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missi
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71389378.
nvd
CVE-2016-0846P3HIGHCVSS 8.4PoCv4.0v4.0.1+20 more2016-04-18
CVE-2016-0846 [HIGH] CWE-264 CVE-2016-0846: libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26877992
nvd
CVE-2017-13208P2CRITICALCVSS 9.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13208 [CRITICAL] CWE-119 CVE-2017-13208: In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing
In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7
nvd
CVE-2016-10229P2CRITICALCVSS 9.8≤ 7.1.12017-04-04
CVE-2016-10229 [CRITICAL] CWE-358 CVE-2016-10229: udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traff
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
nvd
CVE-2017-0411P3HIGHCVSS 7.8PoCv7.0v7.1.0+1 more2017-02-08
CVE-2017-0411 [HIGH] CWE-367 CVE-2017-0411: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd
CVE-2016-6772P3HIGHCVSS 7.8PoCv5.0v5.0.1+7 more2017-01-12
CVE-2016-6772 [HIGH] CWE-264 CVE-2016-6772: An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execu
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31856351.
nvd
CVE-2017-0412P3HIGHCVSS 7.8PoCv7.0v7.1.0+1 more2017-02-08
CVE-2017-0412 [HIGH] CWE-367 CVE-2017-0412: An elevation of privilege vulnerability in the Framework APIs could enable a local malicious applica
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android
nvd