cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 315 of 339
CVE-2024-20123P4MEDIUMCVSS 4.4v12.02024-11-04
CVE-2024-20123 [MEDIUM] CWE-125 CVE-2024-20123: In vdec, there is a possible out of bounds read due to improper structure design. This could lead to In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1569.
nvd
CVE-2024-20112P4MEDIUMCVSS 4.4v13.0v14.02024-11-04
CVE-2024-20112 [MEDIUM] CWE-125 CVE-2024-20112: In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to loc In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.
nvd
CVE-2017-18667P4MEDIUMCVSS 4.3v4.4v5.0+6 more2020-04-07
CVE-2017-18667 [MEDIUM] CWE-20 CVE-2017-18667: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) softw An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can prevent users from learning that SMS storage space has been exhausted. The Samsung ID is SVE-2017-8702 (June 2017).
nvd
CVE-2017-18653P4MEDIUMCVSS 4.3v4.4v5.0+6 more2020-04-07
CVE-2017-18653 [MEDIUM] CVE-2017-18653: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) softw An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. The Email application allows attackers to send emails on behalf of any user via a broadcasted intent. The Samsung ID is SVE-2017-9357 (September 2017).
nvd
CVE-2021-25430P4MEDIUMCVSS 4.3v8.1v9.0+2 more2021-07-08
CVE-2021-25430 [MEDIUM] CWE-287 CVE-2021-25430: Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allo Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
nvd
CVE-2020-0052P4MEDIUMCVSS 4.3v10.0vAndroid-102020-03-10
CVE-2020-0052 [MEDIUM] CWE-306 CVE-2020-0052: In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a p In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479
nvd
CVE-2022-30724P4MEDIUMCVSS 4.3v10.0v11.0+1 more2022-06-07
CVE-2022-30724 [MEDIUM] CWE-280 CVE-2022-30724: Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
nvd
CVE-2022-30725P4MEDIUMCVSS 4.3v10.0v11.0+1 more2022-06-07
CVE-2022-30725 [MEDIUM] CWE-280 CVE-2022-30725: Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
nvd
CVE-2022-30723P4MEDIUMCVSS 4.3v10.0v11.0+1 more2022-06-07
CVE-2022-30723 [MEDIUM] CWE-280 CVE-2022-30723: Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
nvd
CVE-2025-20640P4MEDIUMCVSS 4.3v12.0v13.0+2 more2025-02-03
CVE-2025-20640 [MEDIUM] CWE-125 CVE-2025-20640: In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to loca In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2059.
nvd
CVE-2022-20032P4MEDIUMCVSS 4.1v10.0v11.0+1 more2022-02-09
CVE-2022-20032 [MEDIUM] CWE-362 CVE-2022-20032: In vow driver, there is a possible memory corruption due to a race condition. This could lead to loc In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: ALPS05852822.
nvd
CVE-2023-20750P4MEDIUMCVSS 4.1v13.02023-06-06
CVE-2023-20750 [MEDIUM] CWE-362 CVE-2023-20750: In swpm, there is a possible out of bounds write due to a race condition. This could lead to local i In swpm, there is a possible out of bounds write due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780928.
nvd
CVE-2025-22413P4MEDIUMCVSS 4.0vAndroid kernel2025-08-26
CVE-2025-22413 [MEDIUM] CWE-703 CVE-2025-22413: In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error i In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0083P4MEDIUMCVSS 4.0v12.0v12.1+8 more2025-08-26
CVE-2025-0083 [MEDIUM] CWE-116 CVE-2025-0083: In multiple locations, there is a possible way to access content across user profiles due to URI dou In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35657P4MEDIUMCVSS 4.0v13.0v14.0+4 more2025-09-04
CVE-2023-35657 [MEDIUM] CWE-125 CVE-2023-35657: In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-44128P4LOWCVSS 3.6≥ 4.0, ≤ 13.02023-09-27
CVE-2023-44128 [LOW] CWE-367 CVE-2023-44128: he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete f
nvd
CVE-2017-0691P4MEDIUMCVSS 5.5v7.0v7.1.1+1 more2017-07-06
CVE-2017-0691 [MEDIUM] CWE-190 CVE-2017-0691: A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7 A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36724453.
nvd
CVE-2017-0499P4MEDIUMCVSS 5.5v5.0v5.0.1+9 more2017-03-08
CVE-2017-0499 [MEDIUM] CWE-20 CVE-2017-0499: A denial of service vulnerability in Audioserver could enable a local malicious application to cause A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to the possibility of a temporary denial of service. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32095713.
nvd
CVE-2017-0777P4MEDIUMCVSS 5.5v4.0v4.0.1+27 more2017-09-08
CVE-2017-0777 [MEDIUM] CWE-200 CVE-2017-0777: A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versi A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.
nvd
CVE-2017-0776P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2017-09-08
CVE-2017-0776 [MEDIUM] CWE-200 CVE-2017-0776: A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versi A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.
nvd
Google Android vulnerabilities | cvebase