cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 300 of 339
CVE-2023-20812P4MEDIUMCVSS 4.4v13.02023-08-07
CVE-2023-20812 [MEDIUM] CWE-787 CVE-2023-20812: In wlan driver, there is a possible out of bounds write due to improper input validation. This could In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944987; Issue ID: ALPS07944987.
nvd
CVE-2023-21359P4MEDIUMCVSS 4.4v14.0v142023-10-30
CVE-2023-21359 [MEDIUM] CWE-125 CVE-2023-21359: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9408P4MEDIUMCVSS 4.4vKernel2024-12-05
CVE-2018-9408 [MEDIUM] CWE-125 CVE-2018-9408: In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40636P4MEDIUMCVSS 4.4v11.02023-10-08
CVE-2023-40636 [MEDIUM] CWE-862 CVE-2023-40636: In telecom service, there is a possible way to write permission usage records of an app due to a mis In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed
nvd
CVE-2023-48339P4MEDIUMCVSS 4.4v11.0v12.0+1 more2024-01-18
CVE-2023-48339 [MEDIUM] CWE-862 CVE-2023-48339: In jpg driver, there is a possible missing permission check. This could lead to local information di In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
nvd
CVE-2023-40631P4MEDIUMCVSS 4.4v10.0v11.0+1 more2023-10-08
CVE-2023-40631 [MEDIUM] CWE-862 CVE-2023-40631: In Dialer, there is a possible missing permission check. This could lead to local information disclo In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
nvd
CVE-2024-47028P4MEDIUMCVSS 4.4vAndroid kernel2024-10-25
CVE-2024-47028 [MEDIUM] CWE-190 CVE-2024-47028: In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20788P4MEDIUMCVSS 4.4v15.02025-12-02
CVE-2025-20788 [MEDIUM] CWE-1262 CVE-2025-20788: In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lea In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS10117735; Issue ID: MSV-4539.
nvd
CVE-2025-26417P4MEDIUMCVSS 4.0v12.0v12.1+8 more2025-08-26
CVE-2025-26417 [MEDIUM] CWE-610 CVE-2025-26417: In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user cons In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49739P4MEDIUMCVSS 4.0vAndroid SoC2025-09-04
CVE-2024-49739 [MEDIUM] CWE-787 CVE-2024-49739: In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26421P4MEDIUMCVSS 4.0v13.0v14.0+4 more2025-09-04
CVE-2025-26421 [MEDIUM] CWE-290 CVE-2025-26421: In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26422P4MEDIUMCVSS 4.0v15.0v152025-09-04
CVE-2025-26422 [MEDIUM] CWE-279 CVE-2025-26422: In dump of WindowManagerService.java, there is a possible way of running dumpsys without the require In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22415P4MEDIUMCVSS 4.0v13.0v14.0+2 more2025-09-04
CVE-2025-22415 [MEDIUM] CWE-266 CVE-2025-22415: In android_app of Android.bp, there is a possible way to launch any activity as a system user. This In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28581P4MEDIUMCVSS 4.0v14.0v15.0+8 more2026-06-01
CVE-2026-28581 [MEDIUM] CWE-476 CVE-2026-28581: In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emer In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.
nvd
CVE-2015-1526P4MEDIUMCVSS 5.5≤ 4.4.42017-09-28
CVE-2015-1526 [MEDIUM] CWE-190 CVE-2015-1526: The media_server component in Android allows remote attackers to cause a denial of service via a cra The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.
nvd
CVE-2016-3898P4MEDIUMCVSS 5.5v5.0v5.0.1+5 more2016-09-11
CVE-2016-3898 [MEDIUM] CWE-284 CVE-2016-3898: Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2 Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of service (loss of locked-screen 911 TTY functionality) via a crafted application that modifies the TTY mode by broadcasting an intent, aka internal bug 29832693.
nvd
CVE-2017-0496P4MEDIUMCVSS 5.5v5.0v5.0.1+6 more2017-03-08
CVE-2017-0496 [MEDIUM] CVE-2017-0496: A denial of service vulnerability in Setup Wizard could allow a local malicious application to tempo A denial of service vulnerability in Setup Wizard could allow a local malicious application to temporarily block access to an affected device. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-31554152.
nvd
CVE-2016-3925P4MEDIUMCVSS 5.5v6.0v6.0.1+1 more2016-10-10
CVE-2016-3925 [MEDIUM] CWE-284 CVE-2016-3925: server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked Wi-Fi usage) via a crafted application, aka internal bug 30230534.
nvd
CVE-2015-8893P4MEDIUMCVSS 5.5≤ 6.0.12016-07-11
CVE-2015-8893 [MEDIUM] CWE-119 CVE-2015-8893: app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 and 7 (2013) de app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to cause a denial of service (OS outage or buffer over-read) via a crafted application, aka Android internal bug 28822690 and Qualcomm internal bug CR822275.
nvd
CVE-2016-2424P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-04-18
CVE-2016-2424 [MEDIUM] CWE-20 CVE-2016-2424: server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause a denial of service (reboot loop) via a crafted application, aka internal bug 26513719.
nvd
Google Android vulnerabilities | cvebase